Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\Xml;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -29,14 +29,15 @@ class _XMLReader extends \XMLReader
|
||||
* @param string $encoding The encoding to use, or NULL
|
||||
* @param int $options Bitmask of LIBXML_* constants
|
||||
* @return bool
|
||||
* @note We are disabling the entity loader after opening the content to prevent XXE
|
||||
* @note We are disabling network access while loading the content to prevent XXE
|
||||
*/
|
||||
public function open( $uri, $encoding=NULL, $options=0 )
|
||||
{
|
||||
$entityLoaderValue = libxml_disable_entity_loader( false );
|
||||
$opened = parent::open( $uri, $encoding, $options );
|
||||
libxml_disable_entity_loader( $entityLoaderValue );
|
||||
if( $options === 0 )
|
||||
{
|
||||
$options = LIBXML_NONET;
|
||||
}
|
||||
|
||||
return $opened;
|
||||
return parent::open( $uri, $encoding, $options );
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user