1. Web Security Academy
  2. Server-side template injection
  3. Exploiting
  4. Lab

Lab: Basic server-side template injection

PRACTITIONER

This lab is vulnerable to server-side template injection due to the unsafe construction of an ERB template.

To solve the lab, review the ERB documentation to find out how to execute arbitrary code, then delete the morale.txt file from Carlos's home directory.