- simplexml_load_string: documentation ( source)
<?php
$goodXML = '<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "http://0x.rs/test" >]><foo>&xxe;</foo><test><testing>my value</testing></test>';
$doc = simplexml_load_string($goodXml);
echo $doc->testing;