cookie-based-exploit

1 article
sort: new top best
clear filter
0 7/10

PHP unserialize() can be exploited to achieve RCE through gadget chains—sequences of object destructors and method calls in common frameworks like Monolog. The article demonstrates how to craft serialized payloads targeting real-world applications using tools like phpggc, with a practical example from an ebook webshop that accepted serialized data in cookies.

phpggc Monolog Symfony Laravel Zend Framework Doctrine SyslogUdpHandler BufferHandler DateTime
sjoerdlangkemper.nl · kh4sh3i/bug-bounty-writeups · 22 hours ago · details