Later archive addition
PHPIDS unserialize() Vulnerability: Reusing Framework Object Chains
Explains how PHPIDS turns inspection of attacker input into unsafe PHP object deserialization. In Zend Framework applications, a crafted object graph can chain a logging destructor through mail shutdown and layout rendering to a preg_replace filter, enabling PHP code execution. The advisory traces the existing classes used by the chain and identifies PHPIDS 0.6.3.1 as the fix.
Record
- Researcher
- Stefan Esser
- Published by
- SektionEins
- Date
- Format
- Advisory
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host.