← Back
X-Men | Avishai’s CTF Writeups

Avishai's CTF Writeups

Yalla Balagan! A collection of my CTF writeups and solutions.

View on GitHub

X-Men

The challenge is about XPath injection.

I basically injected this payload ' or '1'='1, and by this way so all the users. Very similar to SQLi

Here you can see the final image using burp suite

final image

The flag is AppSec-IL{!XPaTh_Inj3ct10n@_ForC3}