Server-Side Template Injection with Custom Exploit
DOI:
https://doi.org/10.32628/IJSRSET218318Keywords:
Cyber Security, Vulnerability, Templates, Websecurity, Remote Code Execution, Directory Path Traversal.Abstract
Cyber attacks are getting progressively incessant, causing a great deal of harm. Attackers take our valuable information by compromising web application security loopholes. Dynamic content that is being incorporated into the html that has been served to the client. assume when you open a site page then you see your name so that is dynamic substance for each client who additionally at any point visits that page. We can inject input fields and they are shipped off the web worker. So ,we need to check for all information handled whose worth is reflected in some structure to get the prepared payload. Then attempt to misuse it dependent on the layouts. This paper discusses the idea of an template injection and its impact on template based web application
References
- Vijit Das Noyon, Yeahia Md Abid , Md. Maruf Hassan , Md. Hasan Sharif, Fabiha Nawar Deepa, Rayhanul Islam Rumel, Rafita Haque, Samia Nasrin, Moniruz Zaman. A Study of Ajax Template Injection in Web Applications. https://www.researchgate.net/publication/326668286_A_Study_of_Ajax_Template_Injection_in_Web_Applications
- M. I. Ahmed, M. M. Hassan, and T. Bhuyian. Local File Disclosure Vulnerability: A Case Study of Public-Sector Web Applications https://www.researchgate.net/publication/322236714_Local_File_Disclosure_Vulnerability_A_Case_Study_of_Public-Sector_Web_Applications
- Hossain Shahriar, Sarah M. North, YoonJi Lee and Roger Hu. Server-side code injection attack detection based on Kullback-Leibler distance. https://www.researchgate.net/publication/280768581_Server-Side_Code_Injection_Attack_Detection_Based_on_Kullback-Leibler_Distance
- Yunhui Zheng, Xiangyu Zhang. Path sensitive static analysis of web applications for remote code execution vulnerability detection https://ieeexplore.ieee.org/document/6606611
- Gary Wassermann; Zhendong Su. Static detection of cross-site scripting vulnerabilities. https://ieeexplore.ieee.org/document/4814128
Downloads
Published
Issue
Section
License
Copyright (c) IJSRSET

This work is licensed under a Creative Commons Attribution 4.0 International License.