Security of XML Parse Based on DOM and Its Solution
GU Yun-hua · Computers & Security · 2009
Most XML document processing systems adopt W3C DOM to parse XML documents. There are some bugs when XML document parse system based on DOM deals with DTD, XML comments and XML nodes. Once the bugs are used by malicious XML documents, system will be attacked when it parses them. The paper points out three problems exist in XML parse based on DOM, analyzes why the system is attacked and offers methods of defending it.