Description
The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.
Remediation
References
Related Vulnerabilities
WordPress Plugin RSS for Yandex Turbo Cross-Site Scripting (1.29)
SugarCRM Gain Sensitive Information Vulnerability (CVE-2004-1226)
SharePoint Improper Input Validation Vulnerability (CVE-2019-1295)
MySQL CVE-2016-0662 Vulnerability (CVE-2016-0662)
WordPress Plugin ARPrice-Responsive Pricing Table Cross-Site Request Forgery (2.3)