An Assessment of the Overlooked Dangers of Template Engines
Fuente:
arXiv
Saved in:
| Main Authors: | , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866915826104270848 |
|---|---|
| author | Pisu, Lorenzo Maiorca, Davide Giacinto, Giorgio |
| author_facet | Pisu, Lorenzo Maiorca, Davide Giacinto, Giorgio |
| contents | Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers.
This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2405_01118 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | An Assessment of the Overlooked Dangers of Template Engines Pisu, Lorenzo Maiorca, Davide Giacinto, Giorgio Cryptography and Security Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development. |
| title | An Assessment of the Overlooked Dangers of Template Engines |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2405.01118 |