<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Polyglot on slightlymore</title><link>https://slightlymore.co.uk/tags/polyglot/</link><description>Recent content in Polyglot on slightlymore</description><generator>Hugo</generator><language>en-GB</language><copyright>&lt;a href="https://creativecommons.org/licenses/by/4.0/" target="_blank" rel="license"&gt;CC BY 4.0&lt;/a&gt; by Clinton Montague</copyright><lastBuildDate>Sun, 11 Jan 2026 22:18:42 +0000</lastBuildDate><atom:link href="https://slightlymore.co.uk/tags/polyglot/index.xml" rel="self" type="application/rss+xml"/><item><title>A string to test for template injection vulnerabilities</title><link>https://slightlymore.co.uk/a-string-to-test-for-template-injection-vulnerabilities/</link><pubDate>Sun, 11 Jan 2026 00:00:00 +0000</pubDate><guid>https://slightlymore.co.uk/a-string-to-test-for-template-injection-vulnerabilities/</guid><description>&lt;p&gt;The following string can be used to test a large number of templating engines in one go:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;$ { { &amp;lt; % [ % &amp;#39; &amp;#34; } } % \ .
&lt;/code&gt;&lt;/pre&gt;&lt;blockquote&gt;
&lt;p&gt;[!IMPORTANT]
Remove the spaces between each character! I&amp;rsquo;ve included them here because it messes up rendering in some places!&lt;/p&gt;
&lt;/blockquote&gt;</description></item></channel></rss>