Yes, it was, but the unfortunate side effect is that entities like < and 
" are ignored rather than expanded, which breaks any calls where such 
entities appear in character data.

Scott Nichol

Do not send e-mail directly to this e-mail address,
because it is filtered to accept only mail from
specific mail lists.
----- Original Message ----- 
From: "WJCarpenter" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Saturday, June 25, 2005 3:00 PM
Subject: RE: cvs commit: ws-soap/java/src/org/apache/soap/util/xml 
XMLParserUtils.java


> sn> Modified: java/src/org/apache/soap/util/xml XMLParserUtils.java
> sn> Log: Default expandEntityReferences to true.
> 
> Wasn't that changed to false a while back to thwart DOS stuff in
> malicious XML or something?  (I might be misremembering this from some
> other context.)
> -- 
> [EMAIL PROTECTED] (WJCarpenter)    PGP 0x91865119
> 38 95 1B 69 C9 C6 3D 25    73 46 32 04 69 D6 ED F3
> 
>

Reply via email to