Link to this headingExternal Entity XML Injection
What Are XML External Entity (XXE) Attacks
Link to this headingBypassing Access Controls with XXE
Default Protections:
Php Bypass:
&harmless;
Link to this headingExternal Error XXE
Link to this headingSSRF
Link to this headingSimple HTTP Connection
&xxe;1
HTTP/1.1 400 Bad Request
Content-Type: application/json
Connection: close
Content-Length: 546
"Invalid product ID: {
"Code" : "Success",
"LastUpdated" : "2019-12-12T18:17:44.456491Z",
"Type" : "AWS-HMAC",
"AccessKeyId" : "rNYgGiw5Wwv34YPVSzpN",
"SecretAccessKey" : "m4RaetLQwyQwocJ60xjFJrwYnAJj03K8css1A9Fw",
"Token" : "UCj4myxOKROLlb5wPp5Nahw2fHZsG5n1EkOGokbEtj7uCXa8bwoexc2wiX73Picn2AFwHa44f3Snpz02SuEmZtrTgma9Mr2J3Z48tXICOLyP3HgG5Sf7Q2ArYFZQNZoolTXwsX1jN2u2zTOtpoU0V34kcw0axRCXi9JusZ7z9QDrAWRroWeicvkRrKy7dkocW4MsQWxzINiiF39s4F5vRH7GQaKBahwprLJkd4NwH6PDY2IzlSLYpUxQzuJvS4tA",
"Expiration" : "2025-12-10T18:17:44.456491Z"
}"
Link to this headingGenerate Payloads
Generate DOCX/XLSX/PPTX ODT PDF JPG test files
SVG
PDF
Word Docs
Link to this headingMake a PDF
||
||