WhaleHOUDINI

.. /XXEinjector

Quick Usage

For this tool the run command is:

docker run -it --rm -v <local_dir>:/xxeinjector secsi/xxeinjector --host=<target_ip> --path=/etc --file=<filename> --ssl

Categories

exploitationwebapp

Description

XXEinjector automates retrieving files using direct and out of band methods. Directory listing only works in Java applications. Bruteforcing method needs to be used for other applications.

Official Documentation

Reference: https://github.com/enjoiz/XXEinjector

SecSI LogoHOUDINI

© 2025 — Made with ❤️ bySecSI