Releases: epinna/tplmap
Releases · epinna/tplmap
Exploitation of Python 3 apps, Docker testing environments, TravisCI
Fix docker compose
v0.4.1 Fix docker-compose.yml
Burpsuite module, Dockerized test environments, support for ERB, Slim, Ruby eval, Tornado engines
Marko and doT engines support, detection method improvement
- Improve render detection method
- Skip TLS certificate check
- Add Marko Plugin
- Add doT Plugin
Dust.js engine and generic Python, JavaScript, PHP modules
- Exploitation of Dust.js template engine.
- Fix command execution payloads for Velocity template engine as suggested by @henshin.
- Exploitation of generic code injections for Python, JavaScript and PHP applications.
- Improve how to select the injection points via the command line.
Core, 8 supported engines, blind exploitation, code context escape
- Core
- Detection and exploitation plugins for Mako, Jinja2, Velocity, Freemarker, Jade, Nunjucks, Smarty, Twig
- Blind exploitation
- Code context escape