webPromedium
Fragment YAML
web-kids20
Web application for processing payments (similar to d21/d22, but with YAML). The system validates that the sender equals "me". User input in the "comment" field is inserted into YAML without escaping.
$ ls tags/ techniques/
yaml_fragment_injectionpayment_forgery
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Fragment JSON— web-kids20
- [web][Pro]Fragment XML— web-kids20
- [web][Pro]Cookies— hackerlab
- [web][Pro]Race Shop 2— web-kids20
- [web][Pro]Race Shop— web-kids20