if (isset($_POST['serialize'])) { $s = unserialize($_POST['serialize']); echo $s->name; }
# 此代码是类序列化的结果,如 age=20;name="<script>alert('xss')</script>"; 序列化后是: 我们提交以下代码,将会执行XSS O:4:"User":2:{s:3:"age";i:20;s:4:"name";s:29:"<script>alert('xss')</script>";}