| Engine | Ecosystem | Delimiter Syntax | Simulated Output | Security Significance |
|---|
{{7*7}} is the universal SSTI benchmark: In server-side template injection fuzzing, mathematical multiplication (like 7*7) is universally used because plain text renders literally as {{7*7}}, whereas an active vulnerable template interpreter will parse the AST, evaluate the multiplication operator, and emit the product 49.
About Server-Side Template Injection (SSTI) & Expression Syntax
Server-Side Template Injection occurs when user-supplied input is embedded directly into a template document and parsed by an evaluation engine rather than passed as a data parameter. Attackers exploit SSTI to inspect server environment variables, read arbitrary local files, and achieve Remote Code Execution (RCE).
Standard detection begins with mathematical injection probes such as {{7*7}}, ${7*7}, or <%= 7*7 %>. If the rendered response contains 49 rather than the literal braces, the input boundary has crossed into server template parsing.