[XMLSCHEMA-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

XSV potential issue

From: Cory Virok <cory@dolphtech.com>
Date: Thu, 14 Jul 2005 09:56:23 -0400
Message-ID: <42D66F07.8050206@dolphtech.com>
To: xmlschema-dev@w3.org
potential issue

To whom it may concern,

I was using the XSV utility today, 
(http://www.w3.org/2001/03/webdata/xsv works great! thanks) and saw that 
there was no problems in importing any file on the server within my schema.

Ex: try validating this:

<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:blah="ns" 
elementFormDefault="qualified" attributeFormDefault="unqualified">
    <xs:import namespace="blah" schemaLocation="/etc/passwd"/>
</xs:schema>

You'll get errors, of course since /etc/passwd is not valid XML, but the 
fact that the XSV server has access to it is a potential danger.

Thought you might like to know,
- Cory Virok
Received on Friday, 15 July 2005 04:03:08 GMT

Subscribe to the Stylus Scoop newsletter for helpful XML tips and tutorials.
Email
First Name
Last Name
Company

Download Stylus Studio 6 XML Enterprise Edition

Subscribe in XML format
RSS 2.0
Atom 0.3
Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2007 All Rights Reserved.