Sorry, this page is no longer available
We may earn an affiliate commission when you visit our partners.

XML External Entities (XXE)

Save
May 1, 2024 5 minute read

XML External Entities (XXE) is a type of attack that allows an attacker to access data from systems other than the one they are currently using. This can be a significant security risk, as it can allow attackers to access sensitive information such as databases, files, and even other systems.

Why Learn About XML External Entities (XXE)?

There are several reasons why you might want to learn about XML External Entities (XXE).

Path to XML External Entities (XXE)

Take the first step.
We've curated two courses to help you on your path to XML External Entities (XXE). Use these to develop your skills, build background knowledge, and put what you learn to practice.
Sorted from most relevant to least relevant:

Share

Help others find this page about XML External Entities (XXE): by sharing it with your friends and followers:

Reading list

We've selected 11 books that we think will supplement your learning. Use these to develop background knowledge, enrich your coursework, and gain a deeper understanding of the topics covered in XML External Entities (XXE).
Practical guide to web application security testing. It includes a chapter on XXE, which provides detailed instructions on how to exploit this vulnerability.
This document from the OWASP Foundation provides a detailed overview of XXE in Node.js. It valuable resource for developers who want to learn more about this vulnerability in the context of Node.js.
Provides a comprehensive overview of XML processing in Java, including a section on XXE attacks. It good resource for Java developers who want to learn more about XML security.
Provides a comprehensive overview of web application security, including a chapter on XML external entities (XXE). It valuable resource for developers and security professionals who want to learn more about XXE.
Provides a collection of patterns for securing XML applications, including patterns for preventing XXE attacks. It good resource for developers and security professionals.
Provides a hands-on guide to using WebGoat, a web application penetration testing tool. It includes a section on XXE attacks and provides step-by-step instructions on how to exploit XXE vulnerabilities. It good resource for security researchers and attackers.
Includes a section on XXE attacks and provides information on how to prevent XXE vulnerabilities. It good resource for developers and security professionals.
Includes a section on XXE attacks and provides practical advice on how to prevent XXE vulnerabilities. It good resource for developers and security professionals.
Includes a section on XXE attacks and provides guidance on how to avoid XXE vulnerabilities in C and C++ code. It good resource for developers.
Includes a chapter on XXE attacks and provides detailed information on how to exploit and prevent XXE vulnerabilities. It good resource for security researchers and attackers.
Includes a section on XXE attacks and provides basic information on how to prevent XXE vulnerabilities. It good resource for beginners who want to learn more about web application security.
Table of Contents
Our mission

OpenCourser helps millions of learners each year. People visit us to learn workspace skills, ace their exams, and nurture their curiosity.

Our extensive catalog contains over 50,000 courses and twice as many books. Browse by search, by topic, or even by career interests. We'll match you to the right resources quickly.

Find this site helpful? Tell a friend about us.

Affiliate disclosure

We're supported by our community of learners. When you purchase or subscribe to courses and programs or purchase books, we may earn a commission from our partners.

Your purchases help us maintain our catalog and keep our servers humming without ads.

Thank you for supporting OpenCourser.

© 2016 - 2025 OpenCourser