webPromedium

XXE filter

web-kids20

Task WEB_d242 from the advanced category. The web application is vulnerable to XXE. The flag is hardcoded in the PHP source code. Need to use XXE in combination with php://filter wrapper to read the source code.

$ ls tags/ techniques/
source_code_leakxxe_php_filterbase64_wrapper

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups