Repository navigation
xxe
- Website
- Wikipedia
Top disclosed reports from HackerOne
🎯 XML External Entity (XXE) Injection Payload List
List DTDs and generate XXE payloads using those local DTDs.
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.
An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability
A list of useful payloads for Web Application Security and Pentest/CTF
This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a playground to teach or test with Vulnerability scanners / WAF rules / Secure Configuration settings.
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.
Mole is a framework for identifying and exploiting out-of-band application vulnerabilities.
Go-sec-code is a project for learning Go vulnerability code.