Skip to content
#

applicationsecurity

Here are 27 public repositories matching this topic...

By injecting a malicious XML document containing an external entity, I was able to force the server to process a local file reference. The application returned the contents of the requested system file in the HTTP response, confirming **Arbitrary Local File Disclosure**.

  • Updated Jul 4, 2026

Add this topic to your repo

To associate your repository with the applicationsecurity topic, visit your repo's landing page and select "manage topics."

Learn more