Web Hack List

Collected research

Misconfigurations in Java XML Parsers

Partial hardening of Java XML parsers still leaves XXE and SSRF reachable, because disabling entity expansion or external entities does not stop DTD processing and PUBLIC identifiers still fetch remote URLs. The author also shows the file protocol handler will open an FTP connection to a host taken from a file URL, so blind XXE exfiltration survives a policy permitting only file.

Record

Researcher
Anibal Irrera
Published by
immunityservices.blogspot.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Anibal Irrera, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .