XSLT Server Side Injection (Extensible Stylesheet Language Transformations)
Basic Information
Example - Tutorial
sudo apt-get install default-jdk
sudo apt-get install libsaxonb-java libsaxon-java<?xml version="1.0" encoding="UTF-8"?>
<catalog>
<cd>
<title>CD Title</title>
<artist>The artist</artist>
<company>Da Company</company>
<price>10000</price>
<year>1760</year>
</cd>
</catalog>Fingerprint
Read Local File
SSRF
Versions
Fingerprint
SSRF
Javascript Injection
Directory listing (PHP)
Opendir + readdir
Assert (var_dump + scandir + false)
Read files
Internal - PHP
Internal - XXE
Through HTTP
Internal (PHP-function)
Port scan
Write to a file
XSLT 2.0
Xalan-J extension
Include external XSL
Execute code
php:function
More Languages
Access PHP static functions from classes
More Payloads
Brute-Force Detection List
References
Last updated

