bug72681.phpt 454 B

123456789101112131415161718192021222324
  1. --TEST--
  2. Bug #72681: PHP Session Data Injection Vulnerability
  3. --EXTENSIONS--
  4. session
  5. --SKIPIF--
  6. <?php include('skipif.inc'); ?>
  7. --FILE--
  8. <?php
  9. ini_set('session.serialize_handler', 'php');
  10. session_start();
  11. $GLOBALS['ryat'] = $_SESSION;
  12. $_SESSION['ryat'] = 'ryat|O:8:"stdClass":0:{}';
  13. session_write_close();
  14. session_start();
  15. var_dump($ryat);
  16. var_dump($_SESSION);
  17. ?>
  18. --EXPECT--
  19. array(0) {
  20. }
  21. array(1) {
  22. ["ryat"]=>
  23. string(24) "ryat|O:8:"stdClass":0:{}"
  24. }