diff --git a/PHP serialization/README.md b/PHP serialization/README.md index c237c46..a0c1257 100644 --- a/PHP serialization/README.md +++ b/PHP serialization/README.md @@ -43,6 +43,29 @@ string(68) "O:18:"PHPObjectInjection":1:{s:6:"inject";s:17:"system('whoami');";} ``` +## Authentication bypass + +Vulnerable code: + +```php +