A5:2021 | Security Misconfiguration (3) | Cycubix Docs
XXE example
<?xml version="1.0" standalone="yes" ?>
<!DOCTYPE author [
<!ELEMENT author (#PCDATA)>
<!ENTITY js "Jo Smith">
]>
<author>&js;</author>External DTD declaration
<?xml version="1.0"?>
<!DOCTYPE note SYSTEM "email.dtd">
<email>
<to>[email protected]</to>
<from>[email protected]</from>
<subject>Your app is great, but contains flaws</subject>
<body>Hi, your application contains some SQL injections</body>
</email>XXE

PreviousA5:2021 | Security Misconfiguration (2) | Cycubix DocsNextA5:2021 | Security Misconfiguration (4) | Cycubix Docs
Last updated
Was this helpful?

