Blind XXE with out-of-band interaction via XML parameter entities

Exploitation

the lab has a "check stock" feature that parses XML input

send to repeater

the portswigger labs doesn't allow third partie servers so we have to use collaborator urls instead

so the website is restricting the use of Entities.

let's use parameter entities and try if it will work

hope you found this walkthrough easy to understand and follow

Greeting From Sayonara

Last updated

Was this helpful?