# Lab: Server-side template injection using documentation

We see the following web page

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2FM7kKdFCr4MwNuIy0br15%2Fimage.png?alt=media&#x26;token=f4c416ca-aab9-4a26-828f-7883705093d7" alt=""><figcaption></figcaption></figure>

We login with the credentials we have

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2FW4sSRzfDnPHwjkkAX0LF%2Fimage.png?alt=media&#x26;token=eb99c561-791c-4e25-bd7e-cfed61042535" alt=""><figcaption></figcaption></figure>

With this account, we can edit the posts

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2Fc1lH7p3eRoc7H3jftWmh%2Fimage.png?alt=media&#x26;token=647cb8ee-0791-4f67-9143-1247ec8f54d2" alt=""><figcaption></figcaption></figure>

Trying payloads. We got that:

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2FGx0AVXatSCCi5oNiT82E%2Fimage.png?alt=media&#x26;token=2925a31d-6641-4a4f-b9d2-00ec1898314a" alt=""><figcaption></figcaption></figure>

Let's try with Java

Throwing error, we see Java FreeMarker using

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2FbMbqq07nzmcuvPIoqc9a%2Fimage.png?alt=media&#x26;token=af341f79-8d55-412a-a126-1f3b704c2d5a" alt=""><figcaption></figcaption></figure>

Using code execution

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2F8JIwdUhR1OB2cGTzwzk7%2Fimage.png?alt=media&#x26;token=3a0cf2ff-9eb7-43b0-a893-92626c590008" alt=""><figcaption></figcaption></figure>

So we can remove morale.txt

<figure><img src="https://251574581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlTgE7hbyi7mSyXsMcq44%2Fuploads%2F4F1G3qHf6Jphm4qQU0D1%2Fimage.png?alt=media&#x26;token=8675981f-ab48-4d1c-a408-f970ab8be72f" alt=""><figcaption></figcaption></figure>
