Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion src/main/java/com/acme/xxe/XXEVuln.java
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
package com.acme.xxe;

import javax.xml.XMLConstants;
import org.w3c.dom.Document;
import org.xml.sax.InputSource;
import org.xml.sax.SAXException;
Expand Down Expand Up @@ -33,6 +34,7 @@ public static void main(String[] args)

public static String docToString(final Document poDocument) throws TransformerException {
TransformerFactory transformerFactory = TransformerFactory.newInstance();
transformerFactory.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
Transformer transformer = transformerFactory.newTransformer();
DOMSource domSrc = new DOMSource(poDocument);
StringWriter sw = new StringWriter();
Expand All @@ -44,6 +46,8 @@ public static String docToString(final Document poDocument) throws TransformerEx
public static void saxTransformer(String xml)
throws ParserConfigurationException, SAXException, IOException {
SAXParserFactory spf = SAXParserFactory.newInstance();
spf.setFeature("http://xml.org/sax/features/external-general-entities", false);
spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
spf.setValidating(true);

SAXParser saxParser = spf.newSAXParser();
Expand All @@ -54,14 +58,17 @@ public static void saxTransformer(String xml)
public static Document withDom(String xml)
throws ParserConfigurationException, IOException, SAXException {
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);
dbf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
DocumentBuilder db = dbf.newDocumentBuilder();
return db.parse(new InputSource(new StringReader(xml)));
}

public static Document withDomButDisabled(String xml)
throws ParserConfigurationException, IOException, SAXException {
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
dbf.setExpandEntityReferences(true);
dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);
dbf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
DocumentBuilder db = dbf.newDocumentBuilder();
return db.parse(new InputSource(new StringReader(xml)));
}
Expand Down
1 change: 1 addition & 0 deletions src/main/java/com/acme/xxe/XXEVulnFixed.java
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ public static void main(String[] args)
public static String docToString(final Document poDocument) throws TransformerException {
TransformerFactory transformerFactory = TransformerFactory.newInstance();
transformerFactory.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
transformerFactory.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
Transformer transformer = transformerFactory.newTransformer();
DOMSource domSrc = new DOMSource(poDocument);
StringWriter sw = new StringWriter();
Expand Down
Loading