Re: XML/Parser.php stuff

From: Date: Fri, 04 May 2001 15:28:46 +0000
Subject: Re: XML/Parser.php stuff
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-346@lists.php.net to get a copy of this message
"Tomas V.V.Cox" wrote: > > 2) funcStartHandler and funcEndHandler: Here is a security risk IMHO. > For example if I don't use folding and build an xml file so: ^^^^^^^^^^^^^^^^^^^^^^ Of course I'm wrong, it would work also with folding. > <root> > <parse>foo</parse> > </root> > > The class will call the parse() method (also whichever method from this > class or parents) and do a good mess :) I found a probably great denial of service attack. Using funcStartHandler as tag: <root> <funcStartHandler>foo</funcStartHandler> </root> If the server runs with no exec limit, the infitive loop will consume all the resources. Tomas V.V.Cox

« previous php.pear.dev (#346) next »