Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Beer Recipes Cross-Site Scripting (1.0)
WordPress Plugin Generate PDF using Contact Form 7 Cross-Site Scripting (3.5)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7930)
Oracle Database Server Deserialization of Untrusted Data Vulnerability (CVE-2017-15095)
WordPress Plugin WP Fastest Cache Cross-Site Request Forgery (0.9.0.2)