Slide 32
Slide 32 text
Filtered Unserialize
• Problem: destructor called in unserialized
objects
• allowed_classes option, defaults true (BC)
• __PHP_Incomplete_Class
32
unserialize($data, ["allowed_classes" => true]);
unserialize($data, ["allowed_classes" => false]);
unserialize($data, ["allowed_classes" => [‘UserClass’] ]);