Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Remediation
References
Related Vulnerabilities
Joomla Other Vulnerability (CVE-2006-1048)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.12)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7061)
WordPress Plugin N-Media Website Contact Form with File Upload Arbitrary File Upload (1.3.4)
GeoServer Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-51444)