<?phpinclude'common.php';$requset=array_merge($_GET,$_POST,$_SESSION,$_COOKIE);classdb{public$where;function__wakeup(){if(!empty($this->where)){$this->select($this->where);}}functionselect($where){$sql=mysql_query('select * from user where '.$where);return@mysql_fetch_array($sql);}}if(isset($requset['token'])){$login=unserialize(gzuncompress(base64_decode($requset['token'])));$db=newdb();$row=$db->select('user=\''.mysql_real_escape_string($login['user']).'\'');if($login['user']==='ichunqiu'){echo$flag;}elseif($row['pass']!==$login['pass']){echo'unserialize injection!!';}else{echo"(╯‵□′)╯︵┴─┴ ";}}else{header('Location: index.php?error=1');}?>