Collected research
Misconfigurations in Java XML Parsers
Partial hardening of Java XML parsers still leaves XXE and SSRF reachable, because disabling entity expansion or external entities does not stop DTD processing and PUBLIC identifiers still fetch remote URLs. The author also shows the file protocol handler will open an FTP connection to a host taken from a file URL, so blind XXE exfiltration survives a policy permitting only file.
Record
- Researcher
- Anibal Irrera
- Published by
- immunityservices.blogspot.com
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Anibal Irrera, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .