CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A web application parses XML data submitted by users to generate reports. A penetration tester submits an XML document containing a DOCTYPE declaration that defines an external entity referencing the server's local '/etc/passwd' file, and the application's response includes the file's contents. Which vulnerability was exploited?

  1. ADirectory traversal
  2. BCross-site scripting
  3. CLDAP injection
  4. DXML External Entity (XXE) injection
Show answer & explanation

Correct answer: D. XML External Entity (XXE) injection

XXE injection occurs when a poorly configured XML parser processes external entity references defined in a DOCTYPE declaration, allowing an attacker to read local files, perform SSRF, or cause denial of service. Directory traversal involves manipulating file paths directly in requests, not through XML entity definitions, making XXE the precise vulnerability here.

Why the other options are wrong

  • A. Wrong: directory traversal manipulates file paths in requests directly, not via XML entities.
  • B. Wrong: XSS involves injecting scripts executed in a browser, not XML entity parsing.
  • C. Wrong: LDAP injection manipulates directory service queries, unrelated to XML parsing.

XML External Entity (XXE) Injection

A vulnerability where a poorly configured XML parser processes external entity references, allowing attackers to read local files, perform SSRF, or cause denial of service.

  • Exploits DOCTYPE and ENTITY declarations in XML input
  • Mitigated by disabling external entity processing in parsers
  • Can lead to file disclosure, SSRF, or DoS

Memory trick: XXE: eXtra eXternal Entities let attackers peek at your files.

More Threats, Vulnerabilities, and Mitigations questions