By using / instead of . in class name it's possible to bypass sandbox restrictions.
vulners.com/securityvulns/securityvulns:doc:5285