commit
45c7949118
@ -19,7 +19,7 @@ An entity must be created in the Document Type Definition (DTD), let's start wit
|
||||
<author>&js;</author>
|
||||
----
|
||||
|
||||
So everywhere you use the entity ``&js;` the parser will replace it with the value defined in the entity.
|
||||
So everywhere you use the entity `&js;` the parser will replace it with the value defined in the entity.
|
||||
|
||||
=== What is an XXE injection?
|
||||
|
||||
@ -38,4 +38,4 @@ In general we can distinguish the following kind of XXE attacks:
|
||||
|
||||
* Classic: in this case an external entity is included in a local DTD
|
||||
* Blind: no output and or errors are shown in the response
|
||||
* Error: try to get the content of a resource in the error message
|
||||
* Error: try to get the content of a resource in the error message
|
||||
|
Loading…
x
Reference in New Issue
Block a user