Search

← All tags

Technique CWE-502

Insecure Deserialization

Exploiting deserialisation of untrusted data — Java gadget chains, PHP object injection, Python pickle and YAML exploits.

No published posts yet