Skip to content
← LibraryTechnique entry
W-XXE-CLASSICLateral Movement

XML External Entity (XXE) — Classic

<!ENTITY xxe SYSTEM "file:///etc/passwd"> — included in the response or used to pivot.

§ Where this technique fits

W-XXE-CLASSIC is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.