daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pdf-upload-xxe-and-cors-bypass.md (1196B)


      1 ---
      2 title: "PDF Upload: XXE and Same-Origin Policy Bypass"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/file-upload/pdf-upload-xxe-and-cors-bypass.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-upload/pdf-upload-xxe-and-cors-bypass.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PDF Upload: XXE and Same-Origin Policy Bypass
     14 
     15 PDF files can contain actions, forms, and references to external resources, so an upload feature may expose more than document-rendering risk. The linked research documents historical Adobe Reader issues involving external entities and a same-origin-policy bypass, often described as a **CORS bypass**. Treat its proof of concept as version-specific: reproduce it only with the affected reader and browser integration, and verify current behavior independently.<sup>[[1]](#references)</sup>
     16 
     17 ## References
     18 
     19 - [1] [InsertScript - Multiple PDF Vulnerabilities: Text and Pictures on Steroids](https://insert-script.blogspot.com/2014/12/multiple-pdf-vulnerabilites-text-and.html)