Exploiting XXE using external entities to retrieve files

Exploitation
the lab has a "check stock" feature that parses XML input

send this request to repeater



hope you found this walkthrough easy to understand and follow
Greeting From Sayonara
Last updated
Was this helpful?