Skip to main content
XsiSec.com
HomeReposBlogProjectsPortfolio
© 2026 XsiSec.com
Securitysecurity.txt
Updated 2026-07-30 · v1.0.0+2026-07-30.30ac6e5 · 30ac6e5
  1. Home
  2. ›Blog
  3. ›XML external entity research
Blog topic

XML external entity research

XXE labs and technical notes covering detection, exploitation paths, and secure XML parser configuration.

11
Matching posts
Blind SQL injection with out-of-band data exfiltration – Article cover imageArticle

Blind SQL injection with out-of-band data exfiltration

Exploiting an asynchronous, blind SQL injection vulnerability via Out of Band (OAST) techniques, where the application's TrackingId cookie triggers a…

2025-11-14↗
oob-sqlioracleextract-value
Exploiting XXE via image file upload – Article cover imageArticle

Exploiting XXE via image file upload

Exploiting XXE via image file upload: This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.…

2022-11-17↗
file-uploadlab8portswigger
Exploiting XXE to retrieve data by repurposing a local DTD – Article cover imageArticle

Exploiting XXE to retrieve data by repurposing a local DTD

Exploiting XXE to retrieve data by repurposing a local DTD: This lab’s Check stock feature parses XML input but does not display the result. • PortSw…

2022-11-17↗
xxe
Exploiting XInclude to retrieve files – Article cover imageArticle

Exploiting XInclude to retrieve files

Exploiting XInclude to retrieve files: This lab has a Check stock feature that embeds user input inside a server side XML document, which is then par…

2022-11-16↗
xmlxxe
Exploiting blind XXE to retrieve data via error messages – Article cover imageArticle

Exploiting blind XXE to retrieve data via error messages

Exploiting blind XXE to retrieve data via error messages: Lab: XXE with External DTD and Error Based Exfiltration • PortSwigger • XXE • conditional,…

2022-11-15↗
conditionalxxepasswd
Exploiting blind XXE to exfiltrate data using a malicious external DTD – Article cover imageArticle

Exploiting blind XXE to exfiltrate data using a malicious external DTD

Exploiting blind XXE to exfiltrate data using a malicious external DTD: This lab’s Check stock feature parses XML but doesn't reflect output. My goal…

2022-11-14↗
xxedtd
Blind XXE with out-of-band interaction via XML parameter entities – Article cover imageArticle

Blind XXE with out-of-band interaction via XML parameter entities

Blind XXE with out of band interaction via XML parameter entities: The Check stock endpoint parses XML but: Doesn’t display unexpected values (blind…

2022-11-11↗
in-bandout-of-bandxml
Blind XXE with out-of-band interaction – Article cover imageArticle

Blind XXE with out-of-band interaction

Blind XXE with out of band interaction: The Check stock endpoint parses XML but does not display results. I need to detect blind XXE by triggering ou…

2022-11-11↗
in-bandout-of-bandxml
Exploiting XXE to perform SSRF attacks – Article cover imageArticle

Exploiting XXE to perform SSRF attacks

Exploiting XXE to perform SSRF attacks: The Check stock endpoint parses XML and reflects unexpected values in the response. The lab simulates an EC2…

2022-11-09↗
ssrfxxe
What is  XML and XXE and how does it work? – Article cover imageArticle

What is XML and XXE and how does it work?

What is XML and XXE and how does it work?: XXE:r XML External Entity Injection What is XML External Entity Injection? XML External Entity Injection (…

2022-11-09↗
xmlxxe
Blind SQL injection with out-of-band data exfiltration – Article cover imageArticle

Blind SQL injection with out-of-band data exfiltration

Blind SQL injection with out of band data exfiltration: Exploit a blind SQL injection in the TrackingId cookie to trigger out‑of‑band (OAST) DNS call…

2022-09-12↗
xmloracleblind-sql
Browse the complete archive →