Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

+25 -21
View File
@@ -11,7 +11,7 @@
namespace IPS\Xml;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -28,16 +28,10 @@ class _DOMDocument extends \DOMDocument
* @param string $filename The filename
* @param int $options Bitmask of LIBXML_* constants
* @return bool
* @note We are disabling the entity loader after opening the content to prevent XXE
*/
public function load( $filename, $options=0 )
{
libxml_use_internal_errors(TRUE);
$entityLoaderValue = libxml_disable_entity_loader( false );
$opened = parent::load( $filename, $options );
libxml_disable_entity_loader( $entityLoaderValue );
return $opened;
return static::loadXML( file_get_contents( $filename ), $options );
}
/**
@@ -50,11 +44,19 @@ class _DOMDocument extends \DOMDocument
*/
public function loadHTML( $source, $options=0 )
{
libxml_use_internal_errors(TRUE);
$entityLoaderValue = libxml_disable_entity_loader( false );
libxml_use_internal_errors( TRUE );
/* Turn off external entity loader to prevent XXE */
$entityLoaderValue = libxml_disable_entity_loader( TRUE );
/* Load it */
$opened = parent::loadHTML( $source, $options );
/* Turn external entity loader back to what it was before so we're not messing with other
PHP scripts on this server */
libxml_disable_entity_loader( $entityLoaderValue );
/* Return */
return $opened;
}
@@ -67,13 +69,8 @@ class _DOMDocument extends \DOMDocument
* @note We are disabling the entity loader after opening the content to prevent XXE
*/
public function loadHTMLFile( $filename, $options=0 )
{
libxml_use_internal_errors(TRUE);
$entityLoaderValue = libxml_disable_entity_loader( false );
$opened = parent::loadHTMLFile( $filename, $options );
libxml_disable_entity_loader( $entityLoaderValue );
return $opened;
{
return static::loadHTML( file_get_contents( $filename ), $options );
}
/**
@@ -82,15 +79,22 @@ class _DOMDocument extends \DOMDocument
* @param string $source The HTML to open
* @param int $options Bitmask of LIBXML_* constants
* @return bool
* @note We are disabling the entity loader after opening the content to prevent XXE
*/
public function loadXML( $source, $options=0 )
{
libxml_use_internal_errors(TRUE);
$entityLoaderValue = libxml_disable_entity_loader( false );
libxml_use_internal_errors( TRUE );
/* Turn off external entity loader to prevent XXE */
$entityLoaderValue = libxml_disable_entity_loader( TRUE );
/* Load it */
$opened = parent::loadXML( $source, $options );
/* Turn external entity loader back to what it was before so we're not messing with other
PHP scripts on this server */
libxml_disable_entity_loader( $entityLoaderValue );
/* Return */
return $opened;
}