XSLT Injection
Summary
Tools
Methodology
Determine the Vendor and Version
External Entity
Read Files and SSRF Using Document
Write Files with EXSLT Extension
Remote Code Execution with PHP Wrapper
Remote Code Execution with Java
Remote Code Execution with Native .NET
Labs
References
Last updated