Code Injection via a Vulnerable Template Engine
- Posted by Farah Hawa
- Date March 30, 2022
In this video, I discuss a code injection vulnerability within the Handlebars library. This bug isn’t your usual “template injection” bug.
We will use a vulnerable app to test this, while also looking at some source code to analyze the root cause of the vulnerability. Lastly, after exploiting it successfully, we will see how this can be fixed automatically via Snyk. This is a short intro which can be used
Hi! I work as an application security engineer at Bugcrowd. I'm a part-time bug bounty hunter and I also create technical content for bug bounty hunters & web application pentesters and interview some amazing people in infosec for my YouTube channel: https://www.youtube.com/c/FarahHawa/
You may also like
Why is Continuous Security Monitoring important in cybersecurity?
19 December, 2024
Hacking with Browser Extensions!
7 December, 2024
Buffer Overflow Exploit: A Step-by-Step Tutorial for Beginners
5 December, 2024