Hacksplaining
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance
Sign Up
Log In
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance Sign Up Log In

XML External Entities

By making clever use of external entity references, an attacker can probe your server for files, hang the parser altogether by referencing URLs that never respond, or trigger fraudulent requests on the server-side. Let's look at one potential attack scenario.

An illustration of an XXE attack
Lessons
Glossary
Terms and Conditions
Privacy Policy

© 2026 Hacksplaining Inc. All rights reserved. Questions? Email us at support@hacksplaining.com