⤷ Title: Tryhackme walkthrough | OWASP Top Ten — 2017 | Day — 4 XML External Entity
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Thu, 15 May 2025 13:03:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #xml_external_entities #tryhackme_writeup #owasp_top_10 #tryhackme
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Thu, 15 May 2025 13:03:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #xml_external_entities #tryhackme_writeup #owasp_top_10 #tryhackme
Medium
Tryhackme walkthrough | OWASP Top Ten — 2017 | Day — 4 XML External Entity
Hello, wonderful folks! 😊 Hope you’re all having a fantastic day! Today marks a special occasion as we delve into TryHackMe’s OWASP Top…
⤷ Title: 9.8 CVSS Score: Rockwell Automation Impacted by High-Severity log4net Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 17 May 2025 00:11:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2018_1285 #CVSS #cybersecurity #ICS #industrial automation #log4net #Rockwell Automation #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 17 May 2025 00:11:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2018_1285 #CVSS #cybersecurity #ICS #industrial automation #log4net #Rockwell Automation #XML External Entity #xxe
Daily CyberSecurity
9.8 CVSS Score: Rockwell Automation Impacted by High-Severity log4net Vulnerability
Critical vulnerability (CVSS 9.8) in Rockwell Automation! Learn about the high-risk flaw and how to protect industrial systems.
⤷ Title: Leaky WordPress: Private Post Titles at Risk for 1 Billion Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 00:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Exploit #Hacking #pingback #security vulnerability #Website Security #wordpress #XML_RPC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 00:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Exploit #Hacking #pingback #security vulnerability #Website Security #wordpress #XML_RPC
Daily CyberSecurity
Leaky WordPress: Private Post Titles at Risk for 1 Billion Sites
A WordPress vulnerability puts private information at risk for nearly a billion websites. Can your site's draft titles be stolen?
⤷ Title: CVSS 9.9: Critical XXE Flaw in GeoTools Exposes Geospatial Data Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:34:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Data Breach #geospatial #GeoTools #java #Remote Code Execution #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:34:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Data Breach #geospatial #GeoTools #java #Remote Code Execution #XML External Entity #xxe
Daily CyberSecurity
CVSS 9.9: Critical XXE Flaw in GeoTools Exposes Geospatial Data Systems
A critical XXE vulnerability (CVSS 9.9) in GeoTools llows data disclosure and RCE. Update immediately to patched versions!
⤷ Title: libxml2 Flaws Exposed: Memory Corruption, RCE, & DoS Threats Uncovered
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:02:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Denial of Service #dos #libxml2 #memory corruption #rce #Remote Code Execution #XML parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:02:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Denial of Service #dos #libxml2 #memory corruption #rce #Remote Code Execution #XML parsing
Daily CyberSecurity
libxml2 Flaws Exposed: Memory Corruption, RCE, & DoS Threats Uncovered
Four flaws in libxml2 (CVE-2025-6021, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796) expose systems to memory corruption, RCE, and DoS attacks.
⤷ Title: Critical Apache Jackrabbit Flaw (CVE-2025-53689): XXE Attacks Allow Data Exfiltration & DoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 09:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jackrabbit #CVE_2025_53689 #cybersecurity #data exfiltration #Denial of Service #dos #Java Content Repository #JCR #Vulnerability #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 09:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jackrabbit #CVE_2025_53689 #cybersecurity #data exfiltration #Denial of Service #dos #Java Content Repository #JCR #Vulnerability #XML External Entity #xxe
Daily CyberSecurity
Critical Apache Jackrabbit Flaw (CVE-2025-53689): XXE Attacks Allow Data Exfiltration & DoS
A critical XXE flaw (CVE-2025-53689) in Apache Jackrabbit allows blind XXE attacks for data exfiltration, DoS, or internal file exposure. Update to patched versions immediately!
⤷ Title: Episode 3: XML Injection — When Hidden Tags Rewrite the Story
════════════════════════
𐀪 Author: Yamini Yadav
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 11:07:33 GMT
════════════════════════
⌗ Tags: #injection #ethical_hacking #xml_injection #cybersecurity #application_pen_testing
════════════════════════
𐀪 Author: Yamini Yadav
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 11:07:33 GMT
════════════════════════
⌗ Tags: #injection #ethical_hacking #xml_injection #cybersecurity #application_pen_testing
Medium
Episode 3: XML Injection — When Hidden Tags Rewrite the Story
Hello everyone, hope you all are doing well. So far in this series, we have covered RCE and OS command injection. Now let’s explore XML…
⤷ Title: CVE-2025-54988: Critical XXE Vulnerability in Apache Tika PDF Parser Exposes Sensitive Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Tika #CVE_2025_54988 #cybersecurity #data exfiltration #Vulnerability #XML #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Tika #CVE_2025_54988 #cybersecurity #data exfiltration #Vulnerability #XML #xxe
Daily CyberSecurity
CVE-2025-54988: Critical XXE Vulnerability in Apache Tika PDF Parser Exposes Sensitive Data
A critical XXE flaw in Apache Tika's PDF parser could allow attackers to access sensitive data and pivot into internal networks via crafted PDF files.
⤷ Title: SQL injection in Contexts — JSON, XML, Headers
════════════════════════
𐀪 Author: Ahmed Elsayyad
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 16:21:54 GMT
════════════════════════
⌗ Tags: #sql_injection #json #xml #sqli
════════════════════════
𐀪 Author: Ahmed Elsayyad
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 16:21:54 GMT
════════════════════════
⌗ Tags: #sql_injection #json #xml #sqli
Medium
SQL injection in Contexts — JSON, XML, Headers
We’re used to seeing SQL Injection in query string parameters (like ?id=1) or in forms. But the reality is bigger — any input sent by the…
⤷ Title: Understanding XML and XXE vulnerabilities
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
Medium
Understanding XML and XXE vulnerabilities
Introduction
⤷ Title: Lab 18 : SQL injection with filter bypass via XML encoding
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 05:59:50 GMT
════════════════════════
⌗ Tags: #sql_query_in_xml #xml_sqlite #sql_injection #xml_sql_injection #hackvector_burp_ext
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 05:59:50 GMT
════════════════════════
⌗ Tags: #sql_query_in_xml #xml_sqlite #sql_injection #xml_sql_injection #hackvector_burp_ext
Medium
Lab 18 : SQL injection with filter bypass via XML encoding
This lab contains a SQL injection vulnerability in its stock check feature. The results from the query are returned in the application’s…
⤷ Title: CVE-2025–59287: When WSUS turns from a trusted patch server into an attacker launchpad
════════════════════════
𐀪 Author: Rabbit Knight
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #w3wp #xml_soap #cve_2025_59287 #wsu #rce
════════════════════════
𐀪 Author: Rabbit Knight
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #w3wp #xml_soap #cve_2025_59287 #wsu #rce
Medium
CVE-2025–59287: When WSUS turns from a trusted patch server into an attacker launchpad
In cybersecurity, the worst-case sometimes is a simple one: a trusted internal system (the one you rely on to push updates ) is turned…
⤷ Title: High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
Daily CyberSecurity
High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
GeoServer patched a High-severity XXE flaw (CVE-2025-58360, CVSS 8.2) in its WMS GetMap operation. The flaw allows unauthenticated remote attackers to read arbitrary files and perform SSRF. Update to v2.27.0.
⤷ Title: CRITICAL ALERT: Apache Tika XXE Flaw (CVSS 10.0) Allows File Read via PDF Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Tika #CVE_2025_66516 #Patch Now #PDF Parser #Security Advisory #SSRF #Tika_core #XML External Entity #XXE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Tika #CVE_2025_66516 #Patch Now #PDF Parser #Security Advisory #SSRF #Tika_core #XML External Entity #XXE
Penetration Testing Tools
CRITICAL ALERT: Apache Tika XXE Flaw (CVSS 10.0) Allows File Read via PDF Files
On 4 December 2025, the Apache Software Foundation disclosed a critical vulnerability — CVE-2025-66516, rated the maximum CVSS
⤷ Title: Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
Daily CyberSecurity
Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
A pair of critical security vulnerabilities has been disclosed in the Ruby SAML library, a foundational tool used by developers to implement client-side SAML authorization. Both flaws carry a crit…