1--TEST-- 2Bug #72681: PHP Session Data Injection Vulnerability 3--SKIPIF-- 4<?php include('skipif.inc'); ?> 5--FILE-- 6<?php 7ini_set('session.serialize_handler', 'php'); 8session_start(); 9$_SESSION['_SESSION'] = 'ryat|O:8:"stdClass":0:{}'; 10session_write_close(); 11session_start(); 12var_dump($_SESSION); 13?> 14--EXPECT-- 15array(0) { 16} 17