Web Xxe

XML External Entity injection detection→file-read/SSRF→proof for web apps. Use when the app parses XML you influence - SOAP/REST XML bodies, SAML, RSS/Atom, DOCX/XLSX/SVG/XML file uploads, sitemap import, SVG avatars. Triggers - Content-Type application/xml or text/xml, <?xml, SOAPAction header, SAMLResponse, .docx/.svg upload, XML parse error.

s0ld13rr Updated

File contents

s0ld13rr/pentestcode/tree/main/skills/web/xxe commit ffb46ec290

Frequently asked questions

npx skillmds@latest add s0ld13rr/web-xxe