Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Booster for WooCommerce Cross-Site Scripting (5.6.1)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1576)
Oracle JRE CVE-2013-2433 Vulnerability (CVE-2013-2433)
CKEditor Other Vulnerability (CVE-2022-24729)
WordPress Plugin s2member Secure File Browser Cross-Site Scripting (0.4.16)