![]() ![]() | ![]() |
1.1 ! misho 1: --TEST-- ! 2: Bug #38322 (reading past array in sscanf() leads to segfault/arbitary code execution) ! 3: --FILE-- ! 4: <?php ! 5: ! 6: $str = "a b c d e"; ! 7: var_dump(sscanf("a ",'%1$s',$str)); ! 8: ! 9: echo "Done\n"; ! 10: ?> ! 11: --EXPECTF-- ! 12: int(1) ! 13: Done