OWASP XML External Entity (XXE) Prevention Cheat Sheetarrow-up-right
Timothy Morgan’s 2014 Paper: XML Schema, DTD, and Entity Attacks - A Compendium of Known Techniquesarrow-up-right
Precursor presentation of above paper - at OWASP AppSec USA 2013arrow-up-right
CWE-611: Information Exposure Through XML External Entity Referencearrow-up-right
CWE-827: Improper Control of Document Type Definitionarrow-up-right
Sascha Herzog’s Presentation on XML External Entity Attacks - at OWASP AppSec Germany 2010arrow-up-right
PostgreSQL XXE vulnerabilityarrow-up-right
SharePoint and DotNetNuke XXE Vulnerabilities, in Frencharrow-up-right
XML Denial of Service Attacks and Defenses (in .NET)arrow-up-right
Early (2002) BugTraq Article on XXEarrow-up-right
http://www.synacktiv.fr/ressources/synacktiv_drupal_xxe_services.pdfarrow-up-right
Last updated 4 years ago
Was this helpful?