Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Yudi Zhao, Yuan Zhang 0009, Min Yang 0002. Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs. In Joseph A. Calandrino, Carmela Troncoso, editors, 32nd USENIX Security Symposium, USENIX Security 2023, Anaheim, CA, USA, August 9-11, 2023. pages 3691-3708, USENIX Association, 2023. [doi]

@inproceedings{Zhao0023-0,
  title = {Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs},
  author = {Yudi Zhao and Yuan Zhang 0009 and Min Yang 0002},
  year = {2023},
  url = {https://www.usenix.org/conference/usenixsecurity23/presentation/zhao-yudi},
  researchr = {https://researchr.org/publication/Zhao0023-0},
  cites = {0},
  citedby = {0},
  pages = {3691-3708},
  booktitle = {32nd USENIX Security Symposium, USENIX Security 2023, Anaheim, CA, USA, August 9-11, 2023},
  editor = {Joseph A. Calandrino and Carmela Troncoso},
  publisher = {USENIX Association},
}