Latex Injection 51-73.zip -

🚀 LaTeX Injection - Payloads All The Things

: If shell-escape is enabled, an attacker can run system commands like \write18{ls -la} to list files on the server. latex injection 51-73.zip

: Using \input{/etc/passwd} to trick the server into printing the contents of its system files directly into a PDF. 🚀 LaTeX Injection - Payloads All The Things

If you're building an app that handles LaTeX, consider these defensive steps: and \write18 .

: Use a LaTeX Sanitizer to strip backslashes or dangerous keywords like \input , \include , and \write18 .

Gift this article