diff -r 5a6b6e770365 -r 68c69c656a2c web/lib/Zend/Gdata/YouTube.php --- a/web/lib/Zend/Gdata/YouTube.php Thu May 07 15:10:09 2015 +0200 +++ b/web/lib/Zend/Gdata/YouTube.php Thu May 07 15:16:02 2015 +0200 @@ -16,9 +16,9 @@ * @category Zend * @package Zend_Gdata * @subpackage YouTube - * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com) + * @copyright Copyright (c) 2005-2015 Zend Technologies USA Inc. (http://www.zend.com) * @license http://framework.zend.com/license/new-bsd New BSD License - * @version $Id: YouTube.php 24796 2012-05-12 03:34:26Z adamlundrigan $ + * @version $Id$ */ /** @@ -71,6 +71,8 @@ */ require_once 'Zend/Gdata/YouTube/InboxFeed.php'; +/** @see Zend_Xml_Security */ +require_once 'Zend/Xml/Security.php'; /** * Service class for interacting with the YouTube Data API. @@ -79,7 +81,7 @@ * @category Zend * @package Zend_Gdata * @subpackage YouTube - * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com) + * @copyright Copyright (c) 2005-2015 Zend Technologies USA Inc. (http://www.zend.com) * @license http://framework.zend.com/license/new-bsd New BSD License */ class Zend_Gdata_YouTube extends Zend_Gdata_Media @@ -652,10 +654,10 @@ // Load the feed as an XML DOMDocument object @ini_set('track_errors', 1); $doc = new DOMDocument(); - $success = @$doc->loadXML($response); + $doc = @Zend_Xml_Security::scan($response, $doc); @ini_restore('track_errors'); - if (!$success) { + if (!$doc) { require_once 'Zend/Gdata/App/Exception.php'; throw new Zend_Gdata_App_Exception( "Zend_Gdata_YouTube::parseFormUploadTokenResponse - " .