[XSL-LIST Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

disable-output-UNescaping

Subject: disable-output-UNescaping
From: jon wa <jonni@xxxxxxxxx>
Date: Mon, 28 Oct 2002 20:52:40 +0100 (MET)
unescaping quotes xsl csv
For a project it is convenient to use XSL to generate SQL. This is because
input is XML and in the future we might use a real XML database.
Because malicious XML uploads might try to exploit the SQL I'm worried about
certain characters, mostly quotes, apostrophes and backslashes. My idea was
to escape all these chars with the &#92; notation but I quickly found out
that my XSL always converted this back to a real "\" and the same happened for
apostrophes.

In xsl we have disable-output-escaping to prevent characters being escaped
and I was wondering if it was possible to do the reverse and make sure that
escaped chars are not unescaped during processing.

Thanks.

jw

-- 
+++ GMX - Mail, Messaging & more  http://www.gmx.net +++
NEU: Mit GMX ins Internet. Rund um die Uhr für 1 ct/ Min. surfen!


 XSL-List info and archive:  http://www.mulberrytech.com/xsl/xsl-list


Current Thread

PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.