Skip to content

Bug issue with XXE upload #2

@dugdug36

Description

@dugdug36

Hello,

When i try to make XXE via upload with for example :

Client side:

]>

John
Doe
Doe
&xxe;

Server side:
Error on request:
Traceback (most recent call last):
File "/usr/lib/python2.7/site-packages/werkzeug/serving.py", line 323, in run_wsgi
execute(self.server.app)
File "/usr/lib/python2.7/site-packages/werkzeug/serving.py", line 315, in execute
write(data)
File "/usr/lib/python2.7/site-packages/werkzeug/serving.py", line 273, in write
self.send_response(code, msg)
File "/usr/lib/python2.7/site-packages/werkzeug/serving.py", line 388, in send_response
self.wfile.write(hdr.encode("ascii"))
IOError: [Errno 32] Broken pipe

In addition can you write write-up to know how to exploit every part of this flask ?.
@lokori

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions