webPromedium
Fragment XML
web-kids20
Web application for processing payments. The system validates that the sender equals "me" — you cannot pay from someone else's account. User input in the "comment" field is inserted into the XML document without escaping.
$ ls tags/ techniques/
xml_fragment_injectionpayment_forgery
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Fragment JSON— web-kids20
- [web][Pro]Fragment YAML— web-kids20
- [web][Pro]Easy 1— web-kids20
- [web][Pro]Easy 2— web-kids20
- [web][Pro]Race Shop 2— web-kids20