This box was pretty cool. I learned about XXE, XML parsing, and HTML injection during the test. Starting off I scanned the box We see port 80 is open, so we navigate to the page to see this:
Techobabble for enthusiasts