diff options
author | Christian Heimes <christian@cheimes.de> | 2013-03-26 16:35:55 (GMT) |
---|---|---|
committer | Christian Heimes <christian@cheimes.de> | 2013-03-26 16:35:55 (GMT) |
commit | 7380a67267d9ec59b70617ea59ff31819f530942 (patch) | |
tree | 0648f9c8a5594f0c90ef45c9aefa43440ca7128a /Doc/library/xmlrpc.server.rst | |
parent | 5be6d74a0d0ae111cd823d2b7a5896c77d8c8895 (diff) | |
download | cpython-7380a67267d9ec59b70617ea59ff31819f530942.zip cpython-7380a67267d9ec59b70617ea59ff31819f530942.tar.gz cpython-7380a67267d9ec59b70617ea59ff31819f530942.tar.bz2 |
Issue 17538: Document XML vulnerabilties
Diffstat (limited to 'Doc/library/xmlrpc.server.rst')
-rw-r--r-- | Doc/library/xmlrpc.server.rst | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/Doc/library/xmlrpc.server.rst b/Doc/library/xmlrpc.server.rst index 67feba6..6b4c202 100644 --- a/Doc/library/xmlrpc.server.rst +++ b/Doc/library/xmlrpc.server.rst @@ -16,6 +16,13 @@ servers written in Python. Servers can either be free standing, using :class:`CGIXMLRPCRequestHandler`. +.. warning:: + + The :mod:`xmlrpc.client` module is not secure against maliciously + constructed data. If you need to parse untrusted or unauthenticated data see + :ref:`xml-vulnerabilities`. + + .. class:: SimpleXMLRPCServer(addr, requestHandler=SimpleXMLRPCRequestHandler, logRequests=True, allow_none=False, encoding=None, bind_and_activate=True) Create a new server instance. This class provides methods for registration of |