Dojo Logo
Python3

XXE #1 - Basic File Read

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

Basic File Read

Try to read the contents of /tmp/flag.txt using XML External Entity (XXE) injection.

Solution

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result