Description
The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Participants Database Cross-Site Scripting (1.7.5.9)
MySQL CVE-2016-8284 Vulnerability (CVE-2016-8284)
PHP Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2020-7070)
Internet Information Services Configuration Vulnerability (CVE-1999-0725)
Microsoft SQL Server CVE-2023-36420 Vulnerability (CVE-2023-36420)