Tuesday, 5. November 2002

XXE (Xml eXternal Entity) Attack


XXE (Xml eXternal Entity) attack is an attack on an application that parses XML input from untrusted sources using incorrectly configured XML parser. The application may be coerced to open arbitrary files and/or TCP connections.

¬> Beyond Security Ltd

... Comment