Slide 12
Slide 12 text
GET /exploitation?page=6 HTTP/1.1
• After talking with the dev about these bugs, they looked up the code
to see what exactly was happening
• Turns out, they would also parse it to XML -> XXE?
• You guessed it, it worked!
• PoC was simply to show it made requests to my own server
• Keep in mind, we’re still in the address field!
• Awesome, because of my address, I’ve found 4 high-impact bugs!