⤷ Title: Tryhackme walkthrough | OWASP Top Ten — 2017 | Day — 4 XML External Entity
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Thu, 15 May 2025 13:03:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #xml_external_entities #tryhackme_writeup #owasp_top_10 #tryhackme
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Thu, 15 May 2025 13:03:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #xml_external_entities #tryhackme_writeup #owasp_top_10 #tryhackme
Medium
Tryhackme walkthrough | OWASP Top Ten — 2017 | Day — 4 XML External Entity
Hello, wonderful folks! 😊 Hope you’re all having a fantastic day! Today marks a special occasion as we delve into TryHackMe’s OWASP Top…
⤷ Title: 9.8 CVSS Score: Rockwell Automation Impacted by High-Severity log4net Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 17 May 2025 00:11:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2018_1285 #CVSS #cybersecurity #ICS #industrial automation #log4net #Rockwell Automation #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 17 May 2025 00:11:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2018_1285 #CVSS #cybersecurity #ICS #industrial automation #log4net #Rockwell Automation #XML External Entity #xxe
Daily CyberSecurity
9.8 CVSS Score: Rockwell Automation Impacted by High-Severity log4net Vulnerability
Critical vulnerability (CVSS 9.8) in Rockwell Automation! Learn about the high-risk flaw and how to protect industrial systems.
⤷ Title: Leaky WordPress: Private Post Titles at Risk for 1 Billion Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 00:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Exploit #Hacking #pingback #security vulnerability #Website Security #wordpress #XML_RPC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 00:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Exploit #Hacking #pingback #security vulnerability #Website Security #wordpress #XML_RPC
Daily CyberSecurity
Leaky WordPress: Private Post Titles at Risk for 1 Billion Sites
A WordPress vulnerability puts private information at risk for nearly a billion websites. Can your site's draft titles be stolen?
⤷ Title: CVSS 9.9: Critical XXE Flaw in GeoTools Exposes Geospatial Data Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:34:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Data Breach #geospatial #GeoTools #java #Remote Code Execution #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:34:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Data Breach #geospatial #GeoTools #java #Remote Code Execution #XML External Entity #xxe
Daily CyberSecurity
CVSS 9.9: Critical XXE Flaw in GeoTools Exposes Geospatial Data Systems
A critical XXE vulnerability (CVSS 9.9) in GeoTools llows data disclosure and RCE. Update immediately to patched versions!
⤷ Title: libxml2 Flaws Exposed: Memory Corruption, RCE, & DoS Threats Uncovered
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:02:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Denial of Service #dos #libxml2 #memory corruption #rce #Remote Code Execution #XML parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:02:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Denial of Service #dos #libxml2 #memory corruption #rce #Remote Code Execution #XML parsing
Daily CyberSecurity
libxml2 Flaws Exposed: Memory Corruption, RCE, & DoS Threats Uncovered
Four flaws in libxml2 (CVE-2025-6021, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796) expose systems to memory corruption, RCE, and DoS attacks.
⤷ Title: Critical Apache Jackrabbit Flaw (CVE-2025-53689): XXE Attacks Allow Data Exfiltration & DoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 09:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jackrabbit #CVE_2025_53689 #cybersecurity #data exfiltration #Denial of Service #dos #Java Content Repository #JCR #Vulnerability #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 09:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jackrabbit #CVE_2025_53689 #cybersecurity #data exfiltration #Denial of Service #dos #Java Content Repository #JCR #Vulnerability #XML External Entity #xxe
Daily CyberSecurity
Critical Apache Jackrabbit Flaw (CVE-2025-53689): XXE Attacks Allow Data Exfiltration & DoS
A critical XXE flaw (CVE-2025-53689) in Apache Jackrabbit allows blind XXE attacks for data exfiltration, DoS, or internal file exposure. Update to patched versions immediately!
⤷ Title: Episode 3: XML Injection — When Hidden Tags Rewrite the Story
════════════════════════
𐀪 Author: Yamini Yadav
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 11:07:33 GMT
════════════════════════
⌗ Tags: #injection #ethical_hacking #xml_injection #cybersecurity #application_pen_testing
════════════════════════
𐀪 Author: Yamini Yadav
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 11:07:33 GMT
════════════════════════
⌗ Tags: #injection #ethical_hacking #xml_injection #cybersecurity #application_pen_testing
Medium
Episode 3: XML Injection — When Hidden Tags Rewrite the Story
Hello everyone, hope you all are doing well. So far in this series, we have covered RCE and OS command injection. Now let’s explore XML…
⤷ Title: CVE-2025-54988: Critical XXE Vulnerability in Apache Tika PDF Parser Exposes Sensitive Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Tika #CVE_2025_54988 #cybersecurity #data exfiltration #Vulnerability #XML #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Tika #CVE_2025_54988 #cybersecurity #data exfiltration #Vulnerability #XML #xxe
Daily CyberSecurity
CVE-2025-54988: Critical XXE Vulnerability in Apache Tika PDF Parser Exposes Sensitive Data
A critical XXE flaw in Apache Tika's PDF parser could allow attackers to access sensitive data and pivot into internal networks via crafted PDF files.
⤷ Title: SQL injection in Contexts — JSON, XML, Headers
════════════════════════
𐀪 Author: Ahmed Elsayyad
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 16:21:54 GMT
════════════════════════
⌗ Tags: #sql_injection #json #xml #sqli
════════════════════════
𐀪 Author: Ahmed Elsayyad
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 16:21:54 GMT
════════════════════════
⌗ Tags: #sql_injection #json #xml #sqli
Medium
SQL injection in Contexts — JSON, XML, Headers
We’re used to seeing SQL Injection in query string parameters (like ?id=1) or in forms. But the reality is bigger — any input sent by the…
⤷ Title: Understanding XML and XXE vulnerabilities
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
Medium
Understanding XML and XXE vulnerabilities
Introduction