收藏
回答

确认XXE漏洞是否已修复

商户号:1481984872 ,请帮忙检测验证一下是否已修复,谢谢!


用以上方法验证,解析给定的xml报错,nginx日志也没有打印 "test-xxe-vul"。

错误信息:

java.lang.Exception: org.xml.sax.SAXParseException; lineNumber: 2; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.


Caused by: org.xml.sax.SAXParseException; lineNumber: 2; columnNumber: 10; DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true.

回答关注问题邀请回答
收藏

2 个回答

登录 后发表内容