XXE injection
XXE Injection (XML External Entity Injection)
Key Features of XXE Injection:
Example: External Entity Injection
<!DOCTYPE test [
<!ENTITY x SYSTEM "file:///etc/passwd">
]>
<test>
&x;
</test>Mitigating XXE Vulnerabilities:
XPath Injection
Example: XPath Injection
References
Last updated