[XSL-LIST Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: XSL Injection, is it possible?

Subject: Re: XSL Injection, is it possible?
From: "Dimitre Novatchev" <dnovatchev@xxxxxxxxx>
Date: Mon, 29 May 2006 18:34:23 -0700
xsl injection
There are some applications that allow the end user to enter an XPath
expression (oh, why does this sound somewhat familiar to me :o)    ),
and the possibility for *XPath Injection* is a very real one.

Even if the user is only expected to enter an element name, if the
input is not checked, it may contain an injected XPath expression.

Search for "xpath injection".


-- Cheers, Dimitre Novatchev --------------------------------------- Truly great madness cannot be achieved without significant intelligence.



On 5/29/06, G. T. Stresen-Reuter <tedmasterweb@xxxxxxx> wrote:
Hi,

I have a web-based CMS in which all the data is stored in an XML file.
I use XSL extensively. I take user input and insert it into the XML
file in several different places.

Currently my sanitizing function just escapes <, >, ', and " in the
input but I was wondering if anyone knows of other vectors by which
attackers can enter. Are these characters recognized by the XSLT engine
if they are hex or unicode encoded?

Thanks in advance and I hope this hasn't been covered elsewhere (I
haven't been able to find anything on it).

Ted Stresen-Reuter

Current Thread

PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.