<?php
$xml = <<<XML
<?xml version="1.0" encoding="UTF-8" ?>
<!DOCTYPE foo [
<!ELEMENT foo ANY >
<!ENTITY xxe SYSTEM "http://ss23.geek.nz/viper-test.txt" >
]>
<foo>&xxe;</foo>
XML;
$x = new DOMDocument();
$x->loadXML($xml);
foreach ($x->getElementsByTagName('foo') as $u) {
var_dump($u->nodeValue);
}
- Output for 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38, 5.6.0 - 5.6.40, 7.0.0 - 7.0.33, 7.1.0 - 7.1.33, 7.2.0 - 7.2.33, 7.3.0 - 7.3.33, 7.4.0 - 7.4.33, 8.0.0 - 8.0.30, 8.1.0 - 8.1.28, 8.2.0 - 8.2.18, 8.3.0 - 8.3.6
- string(0) ""
preferences:
233.09 ms | 404 KiB | 406 Q