webPromedium

XXE read

web-kids20

Task WEB_d241 from advanced category. The web application accepts XML data and parses it. The goal is to exploit an XXE (XML External Entity) vulnerability to read local files.

$ ls tags/ techniques/
xxe_file_readexternal_entity_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups