Exploit Xxe

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file upload parsing.

purpleailab 41aa072 5.0 KB Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/exploit/web/xxe commit 41aa072829

Frequently asked questions

npx skillmds@latest add purpleailab/exploit-xxe