|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2015-07-14 19:07 UTC] stas@php.net
-Status: Open
+Status: Feedback
-Type: Security
+Type: Documentation Problem
[2015-07-14 19:07 UTC] stas@php.net
[2015-07-14 20:00 UTC] cmb@php.net
-Status: Feedback
+Status: Verified
-Assigned To:
+Assigned To: cmb
[2015-07-14 20:00 UTC] cmb@php.net
[2015-07-14 20:13 UTC] cmb@php.net
[2015-07-14 20:14 UTC] cmb@php.net
-Status: Verified
+Status: Closed
[2015-07-14 20:14 UTC] cmb@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Sat Oct 10 02:00:02 2026 UTC |
Description: ------------ Hello, the problem here is basically the same described in #69617 for yaml_parse_*. When deserializing a wddx serialized string through wddx_deserialize(), in fact, php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which represents serialized PHP objects. wddx.c:945 if (Z_TYPE_P(ent1->data) == IS_OBJECT) { zval *fname, *retval = NULL; MAKE_STD_ZVAL(fname); ZVAL_STRING(fname, "__wakeup", 1); call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC); Test script: --------------- $ cat wddx.php <?php class Pwn { function __wakeup() { echo "Being called\n"; } } $x = "<wddxPacket version='1.0'><header/><data><struct><var name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>"; wddx_deserialize($x); ?> --------- $ php wddx.php Being called