Skip to content

Latest commit

 

History

History
13 lines (7 loc) · 549 Bytes

vulnerable-code-11.md

File metadata and controls

13 lines (7 loc) · 549 Bytes

SecurityExplained S-23: Vulnerable Code Snippet - 11

Vulnerable Code:

Vulnerable Code

Solution:

This answer is by SonarSource: There are two ways to serialize classes in PHP, both with O: and C:. The second encoding mode is not supported by the blocklist, and arbitrary objects could then be deserialized! It's not enough to get RCE, but it's a good start.

Code Credits: SonarSource

Follow Twitter Thread