Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/65293 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2014/02/03/14 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2014/02/07/7 | third party advisory mailing list |
https://packetstormsecurity.com/files/cve/CVE-2014-1860 | vdb entry third party advisory |
https://www.exploit-database.net/?id=21609 | third party advisory exploit |