General Information

XML Bomb

Variants:
Direct 

Also Known As:
Billion Laughs Attack, XML Quadratic Blowup - Variation

Vector Type:
Attack

Relevance:
Generic

Layer:
Application-Level

Platforms:
Any

Target Type:
Web Application, Web Service

Affected Mechanisms:
Web Server Configuration, Hardening

Invented In:
16/12/2002

Added In:
25/12/2014



Direct Variant:

XML Bomb

Also Known As:
Billion Laughs Attack, XML Quadratic Blowup

Typical Severity:
Major

Learn More: