Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
+25
-21
@@ -11,7 +11,7 @@
|
||||
namespace IPS\Xml;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -28,16 +28,10 @@ class _DOMDocument extends \DOMDocument
|
||||
* @param string $filename The filename
|
||||
* @param int $options Bitmask of LIBXML_* constants
|
||||
* @return bool
|
||||
* @note We are disabling the entity loader after opening the content to prevent XXE
|
||||
*/
|
||||
public function load( $filename, $options=0 )
|
||||
{
|
||||
libxml_use_internal_errors(TRUE);
|
||||
$entityLoaderValue = libxml_disable_entity_loader( false );
|
||||
$opened = parent::load( $filename, $options );
|
||||
libxml_disable_entity_loader( $entityLoaderValue );
|
||||
|
||||
return $opened;
|
||||
return static::loadXML( file_get_contents( $filename ), $options );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -50,11 +44,19 @@ class _DOMDocument extends \DOMDocument
|
||||
*/
|
||||
public function loadHTML( $source, $options=0 )
|
||||
{
|
||||
libxml_use_internal_errors(TRUE);
|
||||
$entityLoaderValue = libxml_disable_entity_loader( false );
|
||||
libxml_use_internal_errors( TRUE );
|
||||
|
||||
/* Turn off external entity loader to prevent XXE */
|
||||
$entityLoaderValue = libxml_disable_entity_loader( TRUE );
|
||||
|
||||
/* Load it */
|
||||
$opened = parent::loadHTML( $source, $options );
|
||||
|
||||
/* Turn external entity loader back to what it was before so we're not messing with other
|
||||
PHP scripts on this server */
|
||||
libxml_disable_entity_loader( $entityLoaderValue );
|
||||
|
||||
|
||||
/* Return */
|
||||
return $opened;
|
||||
}
|
||||
|
||||
@@ -67,13 +69,8 @@ class _DOMDocument extends \DOMDocument
|
||||
* @note We are disabling the entity loader after opening the content to prevent XXE
|
||||
*/
|
||||
public function loadHTMLFile( $filename, $options=0 )
|
||||
{
|
||||
libxml_use_internal_errors(TRUE);
|
||||
$entityLoaderValue = libxml_disable_entity_loader( false );
|
||||
$opened = parent::loadHTMLFile( $filename, $options );
|
||||
libxml_disable_entity_loader( $entityLoaderValue );
|
||||
|
||||
return $opened;
|
||||
{
|
||||
return static::loadHTML( file_get_contents( $filename ), $options );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -82,15 +79,22 @@ class _DOMDocument extends \DOMDocument
|
||||
* @param string $source The HTML to open
|
||||
* @param int $options Bitmask of LIBXML_* constants
|
||||
* @return bool
|
||||
* @note We are disabling the entity loader after opening the content to prevent XXE
|
||||
*/
|
||||
public function loadXML( $source, $options=0 )
|
||||
{
|
||||
libxml_use_internal_errors(TRUE);
|
||||
$entityLoaderValue = libxml_disable_entity_loader( false );
|
||||
libxml_use_internal_errors( TRUE );
|
||||
|
||||
/* Turn off external entity loader to prevent XXE */
|
||||
$entityLoaderValue = libxml_disable_entity_loader( TRUE );
|
||||
|
||||
/* Load it */
|
||||
$opened = parent::loadXML( $source, $options );
|
||||
|
||||
/* Turn external entity loader back to what it was before so we're not messing with other
|
||||
PHP scripts on this server */
|
||||
libxml_disable_entity_loader( $entityLoaderValue );
|
||||
|
||||
/* Return */
|
||||
return $opened;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user