Skip to content
This repository was archived by the owner on Apr 4, 2025. It is now read-only.

Conversation

@aegilops
Copy link
Collaborator

@aegilops aegilops commented Nov 8, 2022

In response to a customer, I created some queries to spot user data tainting XML parsing calls, or calls to parse a string constant filename.

That resulted in three queries. One is the "constant" version, and two are taint queries.

They use a common library that is provided in the same folder.

@GeekMasher
Copy link
Contributor

Can we try to write a test case for this so we can track if these find the use cases we want to find

@GeekMasher GeekMasher merged commit 56a95f5 into main Dec 13, 2022
@GeekMasher GeekMasher deleted the xxe-python-local branch December 13, 2022 15:28
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants