Xxe Injection Methodology

XML外部实体注入(XXE)的检测与利用方法论。当目标有 XML 解析、SOAP API、文件上传(DOCX/XLSX/SVG)、或任何接受 XML 输入的端点时使用。包含基础文件读取、盲 XXE 外带(参数实体+外部DTD)、SVG/DOCX XXE、SOAP Envelope XXE、JSON→XML 转换攻击。即使 API 文档说只接受 JSON,也应尝试 XML Content-Type 测试隐式 XXE。

wgpsec c008d06 5 files · 13.6 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/exploit/web-method/xxe-injection-methodology commit c008d060fa

Frequently asked questions

npx skillmds@latest add wgpsec/xxe-injection-methodology