Collected research
Impossible XXE in PHP
Exploits XXE in PHP code that looks safe: external entity loading off, network access disabled, and DOCTYPE nodes rejected after parsing. Parameter entities expanded while parsing, a system identifier on the DOCTYPE itself, and php filter chains let an attacker read arbitrary server files and exfiltrate them over HTTP or DNS.
Record
- Researcher
- Aleksandr Zhurnakov
- Published by
- PT SWARM
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Aleksandr Zhurnakov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .