1--TEST-- 2libxml_disable_entity_loader() 3--SKIPIF-- 4<?php 5if (!extension_loaded('libxml')) die('skip libxml extension not available'); 6if (!extension_loaded('dom')) die('skip dom extension not available'); 7if (LIBXML_VERSION < 20912) die('skip For libxml2 >= 2.9.12 only'); 8--FILE-- 9<?php 10 11$xml = <<<EOT 12<?xml version="1.0" encoding="UTF-8"?> 13<!DOCTYPE test [<!ENTITY xxe SYSTEM "XXE_URI">]> 14<foo>&xxe;</foo> 15EOT; 16 17$dir = str_replace('\\', '/', __DIR__); 18$xml = str_replace('XXE_URI', $dir . '/libxml_disable_entity_loader_payload.txt', $xml); 19 20function parseXML($xml) { 21 $doc = new DOMDocument(); 22 $doc->resolveExternals = true; 23 $doc->substituteEntities = true; 24 $doc->validateOnParse = false; 25 $doc->loadXML($xml, 0); 26 return $doc->saveXML(); 27} 28 29var_dump(strpos(parseXML($xml), 'SECRET_DATA') !== false); 30var_dump(libxml_disable_entity_loader(true)); 31var_dump(strpos(parseXML($xml), 'SECRET_DATA') === false); 32 33echo "Done\n"; 34?> 35--EXPECTF-- 36bool(true) 37bool(false) 38 39Warning: DOMDocument::loadXML(): I/O warning : failed to load external entity "%s" in %s on line %d 40bool(true) 41Done 42