aboutsummaryrefslogtreecommitdiff
path: root/engine/tests/test_files/xxe/request.xml
diff options
context:
space:
mode:
authorPaweł Sroka <srokap@gmail.com>2014-01-01 13:12:24 +0100
committerPaweł Sroka <srokap@gmail.com>2014-01-01 13:12:24 +0100
commit53509917fd2119e17209179aae6d54b64dd2d244 (patch)
treeaac2e883578b78796686728ae3beed5b2a35a9a4 /engine/tests/test_files/xxe/request.xml
parent7006294fcbfab450289403b6519edb9d5d30ff35 (diff)
parent7cacdc8bc26c98a58dc8986acfd911d6542608af (diff)
downloadelgg-53509917fd2119e17209179aae6d54b64dd2d244.tar.gz
elgg-53509917fd2119e17209179aae6d54b64dd2d244.tar.bz2
Merged in libxml18 (pull request #8)
Disable loading external entities during XML parsing
Diffstat (limited to 'engine/tests/test_files/xxe/request.xml')
-rw-r--r--engine/tests/test_files/xxe/request.xml8
1 files changed, 8 insertions, 0 deletions
diff --git a/engine/tests/test_files/xxe/request.xml b/engine/tests/test_files/xxe/request.xml
new file mode 100644
index 000000000..4390f9db2
--- /dev/null
+++ b/engine/tests/test_files/xxe/request.xml
@@ -0,0 +1,8 @@
+<?xml version="1.0"?>
+<!DOCTYPE foo [
+<!ELEMENT methodName ANY >
+<!ENTITY xxe SYSTEM "%s" >
+]>
+<methodCall>
+ <methodName>test&xxe;test</methodName>
+</methodCall>