xxe-injection-payload-list
XML payload list
Lists examples and types of XML external entity injection payloads and attacks
🎯 XML External Entity (XXE) Injection Payload List
1k stars
23 watching
305 forks
last commit: 7 months ago
Linked from 1 awesome list
bug-bountybugbountycyber-securitycybersecurityhackinginformation-securityinfosecpayloadpayloadsweb-application-securitywebsecuritywebsecurity-referencexmlxml-entityxxexxe-examplexxe-injectionxxe-payloadxxe-payload-listxxe-payloads
Related projects:
Repository | Description | Stars |
---|---|---|
| Provides examples and explanations of vulnerabilities in web applications | 545 |
| A list of examples and explanations for protecting against open redirect vulnerabilities in web applications. | 541 |
| A tool to embed malicious payloads in various document formats | 553 |
| An application used to exploit XXE vulnerabilities by generating XML payloads and serving them to test web applications. | 547 |
| A proof-of-concept web application demonstrating an XML External Entity vulnerability | 225 |
| A collection of payloads designed to exploit vulnerabilities in large language models. | 70 |
| Automates scanning of HTTP resources in a target network using XML External Entity (XXE) attacks | 37 |
| A comprehensive collection of tools and techniques for web application security testing and exploitation | 61,904 |
| Protects against injection attacks by safely escaping untrusted strings in HTML and XML markup | 637 |
| Creates a custom C# beacon payload with AV bypass and shellcode injection capabilities | 20 |
| Automates exploitation of XXE vulnerability using various methods to retrieve files and data from vulnerable applications. | 1,556 |
| A curated list of common words and phrases used in hacking attempts to aid in security testing and assessment | 0 |
| An example of using an entity-component system framework with game engines and physics libraries to create interactive content | 1 |
| A tool for exploiting XXE vulnerabilities in various file formats | 1,049 |
| Prevents users from bypassing predefined insert options by validating and enforcing insertion rules | 1 |