webProeasy
Lab 144 — InsightForge — Blind XXE via XML Data Import
hackadvisor
Task: Flask data analytics platform with XML import endpoint that parses external entities. Solution: Upload XML with DOCTYPE declaring file:///root/flag.txt entity — contents reflected in data_preview JSON response field.
$ ls tags/ techniques/
flaskfile_readpythonnginxxxexmlalpine_linuxmultipart_uploadhoneypot_flagdata_analyticsexternal_entity
xxe_file_readexternal_entity_injectiondecoy_flag_detectionin_band_xxe
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 38 — PipelineForge — XXE in XML Pipeline Import— hackadvisor
- [web][Pro]Lab 316 — InsightForge — JWT Secret Leak to RCE via Command Injection— hackadvisor
- [web][Pro]Lab 116 — InsightForge — IDOR via Undocumented Internal API— hackadvisor
- [web][Pro]Lab 140 — Pressboard — XXE via RSS Feed Import— hackadvisor
- [web][Pro]Lab 13 — WebForge — Insecure Deserialization in Config Import— hackadvisor