> For the complete documentation index, see [llms.txt](https://books.spartan-cybersec.com/web/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://books.spartan-cybersec.com/web/xml-external-entity-xxe-injection.md).

# XML external entity (XXE) injection

- [¿XML external entity?](https://books.spartan-cybersec.com/web/xml-external-entity-xxe-injection/xml-external-entity.md)
- [Lab 1: Exploiting XXE using external entities to retrieve files](https://books.spartan-cybersec.com/web/xml-external-entity-xxe-injection/lab-1-exploiting-xxe-using-external-entities-to-retrieve-files.md): https://portswigger.net/web-security/xxe/lab-exploiting-xxe-to-retrieve-files
- [Lab 2: Exploiting XXE to perform SSRF attacks](https://books.spartan-cybersec.com/web/xml-external-entity-xxe-injection/lab-2-exploiting-xxe-to-perform-ssrf-attacks.md): https://portswigger.net/web-security/xxe/lab-exploiting-xxe-to-perform-ssrf
- [Lab 3: Blind XXE with out-of-band interaction](https://books.spartan-cybersec.com/web/xml-external-entity-xxe-injection/lab-3-blind-xxe-with-out-of-band-interaction.md): https://portswigger.net/web-security/xxe/blind/lab-xxe-with-out-of-band-interaction
