Forcing XXE Reflection through Server Error Messages
Summary
Covers an out-of-band XXE technique that uses an external DTD hosted on an attacker server to exfiltrate local files when the vulnerable application does not reflect responses.
- Published
- Collected
Skip to content