1--TEST-- 2libxml_disable_entity_loader() 3--EXTENSIONS-- 4libxml 5dom 6--SKIPIF-- 7<?php 8if (LIBXML_VERSION < 20912) die('skip For libxml2 >= 2.9.12 only'); 9--FILE-- 10<?php 11 12$xml = <<<EOT 13<?xml version="1.0" encoding="UTF-8"?> 14<!DOCTYPE test [<!ENTITY xxe SYSTEM "XXE_URI">]> 15<foo>&xxe;</foo> 16EOT; 17 18$dir = str_replace('\\', '/', __DIR__); 19$xml = str_replace('XXE_URI', $dir . '/libxml_disable_entity_loader_payload.txt', $xml); 20 21function parseXML($xml) { 22 $doc = new DOMDocument(); 23 $doc->resolveExternals = true; 24 $doc->substituteEntities = true; 25 $doc->validateOnParse = false; 26 $doc->loadXML($xml, 0); 27 return $doc->saveXML(); 28} 29 30var_dump(strpos(parseXML($xml), 'SECRET_DATA') !== false); 31var_dump(libxml_disable_entity_loader(true)); 32var_dump(strpos(parseXML($xml), 'SECRET_DATA') === false); 33 34echo "Done\n"; 35?> 36--EXPECTF-- 37bool(true) 38 39Deprecated: Function libxml_disable_entity_loader() is deprecated in %s on line %d 40bool(false) 41 42%s: DOMDocument::loadXML(): %Sfailed to load %s 43bool(true) 44Done 45