Description
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2002-0147)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2039)
WordPress Plugin Restricted Site Access Unspecified Vulnerability (2.0)
WordPress Plugin oQey Headers 'oqey_settings.php' SQL Injection (0.3)