1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
|
--TEST--
Test unserialize() with array allowed_classes and nonsensical class names
--FILE--
<?php
class foo {
public $x = "bar";
}
$z = array(new foo(), 2, "3");
$s = serialize($z);
try {
unserialize($s, ["allowed_classes" => [""]]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
unserialize($s, ["allowed_classes" => ["245blerg"]]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
unserialize($s, ["allowed_classes" => [" whitespace "]]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
unserialize($s, ["allowed_classes" => ["name\nwith whitespace"]]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
unserialize($s, ["allowed_classes" => ['$dollars']]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
try {
unserialize($s, ["allowed_classes" => ["have\0nul_byte"]]);
} catch (Throwable $e) {
echo $e::class, ': ', $e->getMessage(), "\n";
}
?>
--EXPECT--
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, " whitespace " given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "name
with whitespace" given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "$dollars" given
ValueError: unserialize(): Option "allowed_classes" must be an array of class names, "have" given
|