Commits

Christian Heimes committed 3929794

PHP's libxml_disable_entity_loader() prevents entity expansion

Comments (0)

Files changed (1)

 // $options = LIBXML_NONET;
 $options = LIBXML_NOENT;
 
+/* LIBXML_NOENT doesn't have any effect but
+   libxml_disable_entity_loader(true) works */
+
 $xml = simplexml_load_file($argv[1], "SimpleXMLElement", $options);
 $data = (string)$xml;
 echo strlen($data);