Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Xxe hacking

Shulou Source: shulou.com Published: 2022-06-01 05:04:59 10月02日 Update

Cause of vulnerability:

The parsing of XML files depends on the libxml library, while the previous version of libxml 2.9 supports and enables references to external entities by default. When parsing xml files submitted by users, the server does not properly handle the external entities referenced by xml files (including external ordinary entities and external parameter entities).

Impact:

Common XML parsing methods are: DOMDocument, SimpleXML, XMLReader, these three are based on libxml library parsing XML, so all are affected, xml_parse function is based on expact parser, the default does not load external DTD, unaffected.

Repair:

Php uses libxml_disable_entity_loader (true) to disable the loading of external entities before parsing the xml file.

* Code:

& xxe;EOF;$xml = simplexml_load_string ($xmlstring); print_r ($xml);? >

Tags: Entities files influences appropriateness normal code functions parameters common causes methods vulnerabilities versions users processing support services Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi vpn Microsoft OPPO Reno Docker