# Load XML from External Domains

**URL:** <https://forum.kirupa.com/t/load-xml-from-external-domains/249728>\
**Category:** programming\
**Created:** [January 22, 2008, 1:53am UTC](https://forum.kirupa.com/t/load-xml-from-external-domains/249728 "2008-01-22T01:53:51Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![zemm](https://avatars.discourse-cdn.com/v4/letter/z/4491bb/32.png) [@zemm](https://forum.kirupa.com/u/zemm)\
**Post date:** [January 22, 2008, 1:53am UTC](https://forum.kirupa.com/t/load-xml-from-external-domains/249728/1 "2008-01-22T01:53:51Z")

</div>

I was looking at [http://www.kirupa.com/web/load\_xml.htm](http://www.kirupa.com/web/load_xml.htm) and it is a very bad example!

One should use readfile() instead of include(). Then the \<? ?\> tags will not be executed as PHP. Using include opens up all kinds of security issues: What if someone passed a URL they controlled? Then they could run arbitrary code on your server!

The comment “I[FONT=Arial][SIZE=2]f that tag is included in the XML-file, it will cause a PHP parse error, since php will treat everything within the \<? and ?\> as PHP-code” should have sent off alarm bells.

Also, if you turn off short\_open\_tags then \<? will be ignored and you’ll require \<?php ?\> for all PHP code.  
[/SIZE][/FONT]
