All tools

Web Application

Tplmap

Server-Side Template Injection detection and exploitation tool.

intermediate
Linux
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Suspect SSTI in template-driven apps (Jinja, Twig, etc.).

How

Point at parameter; detect engine; get RCE in lab if vulnerable.

Why

SSTI often equals RCE — important class to recognize.

Commands & usage

tplmap -u 'http://target/page?name=John'

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

ssti
web

Related in Web Application