1--TEST-- 2Bug #72731: Type Confusion in Object Deserialization 3--FILE-- 4<?php 5 6class obj { 7 var $ryat; 8 function __wakeup() { 9 $this->ryat = 0x1122334455; 10 } 11} 12 13$poc = 'O:8:"stdClass":1:{i:0;O:3:"obj":1:{s:4:"ryat";R:1;}}'; 14var_dump(unserialize($poc)); 15 16?> 17--EXPECTF-- 18%s(73588229205) 19