TInjA
TInjA copied to clipboard
TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight different programming languages.
When passing something like a post request or even get request all parameters will be tested , I thought maybe there is something like * in sqlmap but it didn't...
TInjA is not able to identify the ERB template under https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-basic. It seems the file https://github.com/Hackmanit/TInjA/blob/main/pkg/engines.go needs to be updated. Thanks! Best regards, Ricardo Iramar