Content area

Abstract

SQL Injection is a common Web application attack, and XML is vulnerable to it as well. Validating your incoming XML documents against XML schema doesn't necessarily prevent this attack. That's because the type "xsdistring" does not preclude special characters and specific SQL keywords that are, after all, of the correct type. To prevent ISO character sets from being exploited, declare the ISO character set you're using for translating Unicode input into ASCII.

Details

1007133
Business indexing term
Title
The XML Factor
Publication title
Volume
15
Issue
11
Pages
79-82
Number of pages
3
Publication year
2004
Publication date
Jun 10, 2004
Section
WORKSHOP
Publisher
Informa
Place of publication
Manhasset
Country of publication
United States
ISSN
10464468
Source type
Trade Journal
Language of publication
English
Document type
Feature
ProQuest document ID
215438478
Document URL
https://www.proquest.com/trade-journals/xml-factor/docview/215438478/se-2?accountid=208611
Copyright
Copyright CMP Media LLC Jun 10, 2004
Last updated
2024-11-19
Database
ProQuest One Academic