bug72681.phpt 431 B

12345678910111213141516171819202122
  1. --TEST--
  2. Bug #72681: PHP Session Data Injection Vulnerability
  3. --SKIPIF--
  4. <?php include('skipif.inc'); ?>
  5. --FILE--
  6. <?php
  7. ini_set('session.serialize_handler', 'php');
  8. session_start();
  9. $GLOBALS['ryat'] = $_SESSION;
  10. $_SESSION['ryat'] = 'ryat|O:8:"stdClass":0:{}';
  11. session_write_close();
  12. session_start();
  13. var_dump($ryat);
  14. var_dump($_SESSION);
  15. ?>
  16. --EXPECT--
  17. array(0) {
  18. }
  19. array(1) {
  20. ["ryat"]=>
  21. string(24) "ryat|O:8:"stdClass":0:{}"
  22. }