The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How is PHP Object Injection is reported by burp extension "PHP Object Injection Check"?

chandraveer | Last updated: Mar 01, 2018 08:38AM UTC

While scanning the XVWA (Xtreme Vulnerable Web Application) consisting the vulnerability-PHP Object Injection i.e. Insecure Deserialization, burp extension "PHP Object Injection Check" doesn't report with the same name. As burp insert payload PDO object also means plug-in is working, but vulnerability is not getting reported. If there are any prerequisites for using this plugin, please suggest one.

PortSwigger Agent | Last updated: Mar 01, 2018 10:15AM UTC