Changes

Jump to: navigation, search

InsomniHack-2013/Web2/WanderShop

75 bytes added, 10:57, 26 March 2013
/* Solution */
</basket>
</pre>
* We can then inject XML with the cookie, we use [https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing XML external entities ] which allow to manipulate local files and display the result in the XML
<pre>
<!DOCTYPE basket
ControlGroup, administrator
4,205
edits