1--TEST-- 2libxml_disable_entity_loader() 3--SKIPIF-- 4<?php 5if (!extension_loaded('libxml')) die('skip libxml extension not available'); 6if (!extension_loaded('dom')) die('skip dom extension not available'); 7if (LIBXML_VERSION >= 20912) die('skip For libxml2 < 2.9.12 only'); 8?> 9--FILE-- 10<?php 11 12$xml = <<<EOT 13<?xml version="1.0" encoding="UTF-8"?> 14<!DOCTYPE test [<!ENTITY xxe SYSTEM "XXE_URI">]> 15<foo>&xxe;</foo> 16EOT; 17 18$dir = str_replace('\\', '/', __DIR__); 19$xml = str_replace('XXE_URI', $dir . '/libxml_disable_entity_loader_payload.txt', $xml); 20 21function parseXML($xml) { 22 $doc = new DOMDocument(); 23 $doc->resolveExternals = true; 24 $doc->substituteEntities = true; 25 $doc->validateOnParse = false; 26 $doc->loadXML($xml, 0); 27 return $doc->saveXML(); 28} 29 30var_dump(strpos(parseXML($xml), 'SECRET_DATA') !== false); 31var_dump(libxml_disable_entity_loader(true)); 32var_dump(strpos(parseXML($xml), 'SECRET_DATA') === false); 33 34echo "Done\n"; 35?> 36--EXPECTF-- 37bool(true) 38 39Deprecated: Function libxml_disable_entity_loader() is deprecated in %s on line %d 40bool(false) 41 42Warning: DOMDocument::loadXML(): I/O warning : failed to load external entity "%s" in %s on line %d 43 44Warning: DOMDocument::loadXML(): Failure to process entity xxe in Entity, line: %d in %s on line %d 45 46Warning: DOMDocument::loadXML(): Entity 'xxe' not defined in Entity, line: %d in %s on line %d 47bool(true) 48Done 49