Aug 23 2008
User: cedric
Category: Ruby on Rails
Tags: ruby security

Dos vulnerability in REXML

There is a DoS vulnerability in the REXML library used by Rails to parse incoming XML requests. A so-called “XML entity explosion” attack technique can be used for remotely bringing down (disabling) any application which parses user-provided XML. Most Rails applications will be vulnerable to this attack.

Announcement

comments : 0 Add comment

Back
Log in

Quick links

Localization

Search

weather


  • metric us

gallery

  •  
    IMG_1404.JPG
     

Last comments

Categories

  • categories

nabaztag

  • message

    left
    right
    voice
    speed
    pitch

hcard