logo

Revisting XXE and abusing protocols

ID: a8db07e7-34a4-509a-bcb6-81be56378363

STIX ID: report--a8db07e7-34a4-509a-bcb6-81be56378363

Feed Name: SensePost Blog

Threat Score
65/100

Date Published: 2014-01-28

Date Updated: 2026-04-29

...
...

This report demonstrates a proof-of-concept XML External Entity (XXE) vulnerability in OpenID YADIS discovery. The author crafts malicious XRDS documents that cause victim servers to fetch attacker-controlled resources, enabling file exfiltration (using php://filter to base64-encode files) and, where PHP handlers are available, remote code execution (expect://). The write-up includes payload examples, test results, and a mitigation recommendation to disable entity loading in libxml.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.