XML: eXploitable Markup Language

XPath injection on XML files
Quill icon Rafael Ballestas   Folder icon attacks   Tag icon xml,  xpath,  injection

Markup languages are “systems for annotating a document in a way that is syntactically distinguishable from the text.” [1] What does that really mean? I reckon that’d be better understood with examples. But before, a warning: if you use them for sensitive information storage, you should be really careful …

