Shocking News in PHP Exploitation¶
Esser, S. (2009). Shocking News in PHP Exploitation.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Domain-specific¶
- Insecure Deserialization
- PHP's
unserializetriggers magic methods (__wakeup,__destruct) that an attacker can chain into a gadget sequence reaching arbitrary computationThis sourceIt does not carry the generalization that such chains have recurred across CMS plugin ecosystems, which is not cited to this source. Author, subject and year were checked; the venue named above, Power of Community (POC) 2009, was not independently confirmed.
- PHP's
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:9527786dee90 · see in the full table