XPath injection mitigation

后端 未结 3 528
情深已故
情深已故 2020-12-07 02:42

Are there any pre-existing methods in .NET to detect/prevent an xpath injection attack?

I can forsee 2 examples but there are likely many more.

e.g.

3条回答
  •  有刺的猬
    2020-12-07 03:25

    Just avoid building XPath expressions using string concatenation. Use parameters/variables instead.

提交回复
热议问题