PHP Object Injection 漏洞总结 漏洞概述 PHP Object Injection 是一种应用层漏洞,允许攻击者执行多种恶意操作,如代码注入、SQL 注入、路径遍历和应用拒绝服务。该漏洞发生在用户输入未经过适当清理就传递给未序列化的 PHP 函数时。由于 PHP 支持对象序列化,攻击者可以传递恶意的序列化字符串到易受攻击的 调用,从而将任意 PHP 对象注入到应用作用域中。 影响范围 条件: - 应用程序必须包含一个实现了 PHP 魔术方法(如 或 )的类,这些方法可用于执行恶意攻击或启动“POP 链”。 - 攻击期间使用的所有类必须在调用易受攻击的 时声明,否则需要支持对象自动加载。 修复方案 不要使用 函数处理用户提供的输入,建议使用 JSON 函数代替。 示例代码 Example 1 Example 2 Example 3 相关控制 输入验证 静态代码分析 参考链接 PHP: unserialize PHP: Magic Methods PHP: Autoloading Classes PHP RFC: Secured unserialize() Shocking News in PHP Exploitation Stefan Esser, POC 2009 Utilizing Code Reuse/ROP in PHP Application Exploits Stefan Esser, BlackHat USA 2010 类别 Injection 编辑 Edit on GitHub 赞助商 Spotlight: Arnica Corporate Supporters: GuidePoint, Guardsquare, Check Point, Bloomberg, SQL, Fortify, Adobe, SCSK 隐私政策 Privacy Sitemap Contact 版权声明 OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Call, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc. Unless otherwise specified, all content on the site is Creative Commons Attribution-ShareAlike v4.0 and provided without warranty of service or accuracy. For more information, please refer to our General Disclaimer. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. Copyright 2026, OWASP Foundation, Inc.