system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
| Software | From | Fixed in |
|---|---|---|
| anchorcms / anchor_cms | 0.9.3-beta | 0.9.3-beta.x |
| anchorcms / anchor_cms | 0.9.1 | 0.9.1.x |
| anchorcms / anchor_cms | 0.9.2 | 0.9.2.x |
| anchorcms / anchor_cms | 0.9.3 | 0.9.3.x |
| anchorcms / anchor_cms | 0.9.3-alpha | 0.9.3-alpha.x |