mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 03:02:30 +00:00
977 B
977 B
CVE-2016-4010
Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
POC
Reference
- https://packetstormsecurity.com/files/137121/Magento-Unauthenticated-Arbitrary-File-Write.html
- https://packetstormsecurity.com/files/137312/Magento-2.0.6-Unserialize-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/39838/