Top 10 winner
Exploiting XXE with local DTD files
Blind XXE usually needs an attacker-hosted DTD because the internal subset forbids a parameter entity inside markup. Loading a DTD file that already exists on the target host and redefining one of its parameter entities smuggles that nesting into the internal subset, so file contents are returned in a parser error message with no outbound network access.
Record
- Researcher
- Arseniy Sharoglazov and @_mohemiv
- Published by
- mohemiv.com
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Arseniy Sharoglazov and @_mohemiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .