On Thu, Sep 11, 2008 at 08:54:15AM +0200, Frederik Ramm wrote:
> Subject: Re: [OSM-dev] Invalid XML?
> 
> Hi,
> 
> Florian Lohoff wrote:
> >Its not that the xml is broken afterwards but people could start putting
> >bad things into the database by closing a tag and reopening a new one.
> 
> Excuse me? How do you think that could happen?
> 
> The backslash has no special meaning in XML, it is just a character like 
> any other. It does not require escaping.

I stand corrected - you are right - at least the main api escapes ">< so
one can not inject tags into tag names or values.

I need to think about other ways *evil grin*

Flo
-- 
Florian Lohoff                  [EMAIL PROTECTED]             +49-171-2280134
        Those who would give up a little freedom to get a little 
          security shall soon have neither - Benjamin Franklin

Attachment: signature.asc
Description: Digital signature

_______________________________________________
dev mailing list
dev@openstreetmap.org
http://lists.openstreetmap.org/listinfo/dev

Reply via email to