Hello Friends,

I’m Rem01x And I’m Currently Preparing For The eWPTX Exam So I Will Be Walking Through All PortSwigger Labs And Make Sure To Make Writeups For All Of Them.

Let’s Start Now.

Assume that we have this website.

Untitled

Now, let’s recon the website.

Untitled

Now, we are logged in as wiener.

Untitled

Please notice the POST request to change the author display.

Untitled

Now, try to inject the SSTI payload over there and then send.

}}{{7*7}}

Now, go to any post and write a comment,

Untitled

Notice, our name is Peter49 —> were 49 is the SSTI payload.

Now, at the same POST request let’s try to cause an error.

}}{{7/0}}