Courseiva
hardMultiple Choice

PT0-002 Practice Question: During an internal test, a penetration tester…

During an internal test, a penetration tester discovers a web application that is vulnerable to Server-Side Template Injection (SSTI). The application uses a template engine that does not sandbox user input. Which of the following payloads would be MOST effective to achieve remote code execution on the server?

⚠ Common exam trap

Many candidates confuse SSTI with simple template injection tests (like `{{7*7}}`) or XSS, failing to recognize that the correct payload must chain object introspection to access system commands for RCE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{{config.__class__.__init__.__globals__['os'].popen('id').read()}}

It exploits Python's object model to access the `os` module via `__class__.__init__.__globals__`, bypassing the template engine's lack of sandboxing. This allows the attacker to execute arbitrary system commands like `id` on the server, achieving remote code execution (RCE). The payload is specific to Jinja2 or similar Python-based template engines that expose built-in objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {{7*7}}

    Why it's wrong here

    This expression is evaluated by Jinja2 as 49, which may confirm the presence of a template injection vulnerability but does not grant code execution. In Jinja2, {{7*7}} performs arithmetic directly in the template context, never leaving the template's sandbox to access Python builtins or system commands. A working SSTI proof-of-concept must chain object attributes and methods to reach dangerous functions, not just produce a computed value.

  • ✗

    <script>alert('xss')</script>

    Why it's wrong here

    This payload attempts cross-site scripting (XSS), which executes JavaScript in the victim's browser, not server-side code. SSTI payloads must be interpreted by the server-side template engine, and the syntax <script>alert('xss')</script> is passed through verbatim or rendered as text, depending on the engine, but it does not interact with the underlying Python environment. Even if the script executes in a browser, it does not prove or exploit server-side code execution.

  • ✗

    ${7*7}

    Why it's wrong here

    The ${...} syntax is used by Java-based template engines such as Thymeleaf and FreeMarker for variable substitution, not by Python's Jinja2 which uses {{...}}. If the application uses Jinja2, ${7*7} is treated as literal text and does not even validate the injection point. While it could evaluate as 49 in a different engine, it still lacks the object traversal needed to escalate from expression evaluation to remote code execution.

  • ✓

    {{config.__class__.__init__.__globals__['os'].popen('id').read()}}

    Why this is correct

    This is the canonical Jinja2 SSTI-to-RCE payload. It chains Python object introspection: config (a Jinja2 global) → __class__ (its class) → __init__ (constructor) → __globals__ (dictionary of global variables) to reach the 'os' module, then calls popen('id').read() to execute a system command and return its output. This abuses the fact that Jinja2 allows attribute access and method calls on Python objects without proper sandboxing, granting full server-side code execution.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.