3.-XML-external-entity-xxe-injection
Introduction to XXE
XML Basics
XML Structure:
Exploitation Techniques
1. Local File Disclosure
2. Source Code Disclosure (PHP Filter)
3. Remote Code Execution (RCE) with Expect
4. CDATA Exfiltration via External DTD
5. Error-Based XXE with External DTD
6. Out-of-Band (OOB) Exfiltration with External DTD
7. Automated XXE Exploitation with XXEinjector
XXE Prevention
Key Takeaways
Last updated