There are situations where XML external entity resolution is necessary; 
users must consider the vulnerabilities inherent in resolving XML 
external entities in untrusted documents. Disabling external entity 
resolution is a safe default.

