FEUP-M.EIC025-2023/2024-2S
Portswigger Labs
Exploiting XXE using external entities to retrieve files
Exploiting blind XXE to exfiltrate data using a malicious external DTD
Limit overrun race conditions
Single-endpoint race conditions
Modifying serialized objects
Using application functionality to exploit insecure deserialization
Basic SSRF against the local server
SSRF with blacklist-based input filter