[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: Entities can execute system level commands?

  • From: David Carlisle <davidc@nag.co.uk>
  • To: "Costello, Roger L." <costello@mitre.org>
  • Date: Mon, 19 Jul 2010 14:20:19 +0100

Re:  Entities can execute system level commands?
On 19/07/2010 14:08, Costello, Roger L. wrote:
 > How can the use of an entity result


saying an xml file may contain system commands that may be executed is 
like saying an ascii file might contain commands.

It all depends what the xml is, if it is xslt or ant or ... then more or 
less by definition it contains commands that may be executed, and 
executing commands you have obtained from elsewhere has obvious security 
implications, which is why it is mentioned in that section.


Note by the way that when the mime specs talk of "entity" they mean what 
xml calls a document (or external parsed entity). so you don't need to 
give an example using  <!ENTITY it's not talking about xml entity 
references.


as noted in the rfc that you cite:

   (Note that, as sometimes happens between two communities, both MIME
    and XML have defined the term entity, with different meanings.)


David

________________________________________________________________________
The Numerical Algorithms Group Ltd is a company registered in England
and Wales with company number 1249803. The registered office is:
Wilkinson House, Jordan Hill Road, Oxford OX2 8DR, United Kingdom.

This e-mail has been scanned for all viruses by Star. The service is
powered by MessageLabs. 
________________________________________________________________________


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.