Case log
3 write-ups across 2 categories. Filter below.
An XML external entity injection let me read arbitrary files off the server by hijacking a field that reflected parsed XML values back in the response.