Web Xxe

XML External Entity injection → file read, SSRF, sometimes RCE. Load when the app parses XML you supply: SOAP, SAML, XML APIs, SVG/DOCX/XLSX upload, RSS import, `Content-Type: application/xml`. Signals: XML request bodies, "<?xml", SAML responses, file parsers.

NoorQureshi 837a0c8 2 files · 4.7 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-xxe commit 837a0c80a9

Frequently asked questions

npx skillmds@latest add noorqureshi/web-xxe