90017—XSLT Injection
PUBLISHEDsecurity alertMedium
Active
Metadata
摘要
Injection using XSL transformations may be possible, and may allow an attacker to read system information, read and write files, or execute arbitrary code.
解决方案
Sanitize and analyze every user input coming from any client-side.