mirror of
https://github.com/php/php-src.git
synced 2026-04-20 14:31:06 +02:00
16 lines
718 B
PHP
16 lines
718 B
PHP
--TEST--
|
|
Bug #72142: WDDX Packet Injection Vulnerability in wddx_serialize_value()
|
|
--SKIPIF--
|
|
<?php if (!extension_loaded("wddx")) print "skip"; ?>
|
|
--FILE--
|
|
<?php
|
|
|
|
$wddx = wddx_serialize_value('', '</comment></header><data><struct><var name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket>');
|
|
var_dump($wddx);
|
|
var_dump(wddx_deserialize($wddx));
|
|
|
|
?>
|
|
--EXPECT--
|
|
string(301) "<wddxPacket version='1.0'><header><comment></comment></header><data><struct><var name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket></comment></header><data><string></string></data></wddxPacket>"
|
|
string(0) ""
|