Files
cve/2013/CVE-2013-1465.md
2025-09-29 21:09:30 +02:00

785 B

CVE-2013-1465

Description

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.

POC

Reference

Github

No PoCs found on GitHub currently.