XXE
XML External Entities. Places that use PHP also usually use XML
Last updated
XML External Entities. Places that use PHP also usually use XML
Last updated
If you find a request submitting data in XML try adding:
You can also change the entity to begin receiving files:
Or to go download a url:
And then run commands:
Requires the PHP 'expect' module to be enabled on the target web server