Web Hack List

Collected research

PHPIDS unserialize() Vulnerability: Reusing Framework Object Chains

Advisory 02/2009: PHPIDS unserialize() Vulnerability

Explains how PHPIDS turns inspection of attacker input into unsafe PHP object deserialization. In Zend Framework applications, a crafted object graph can chain a logging destructor through mail shutdown and layout rendering to a preg_replace filter, enabling PHP code execution. The advisory traces the existing classes used by the chain and identifies PHPIDS 0.6.3.1 as the fix.

Record

Document
Advisory 02/2009: PHPIDS unserialize() Vulnerability
Researcher
Stefan Esser
Published by
SektionEins
Date
Format
Advisory
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .