Magento是美国Magento公司的一套开源的PHP电子商务系统,它提供权限管理、搜索引擎和支付网关等功能。Magento Server是Magento服务器。MAGMI(又名Magento Mass Importer)是其中的一个用于将大量的产品目录导入到Magento系统中的插件。 Magento Server MAGMI插件中的web/ajax_pluginconf.php脚本存在目录遍历漏洞。远程攻击者可借助‘file’参数中的目录遍历字符‘..’利用该漏洞读取任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Magento Server MAGMI (aka Magento Mass Importer) contains a directory traversal vulnerability in web/ajax_pluginconf.php. that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-2067.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2015-2070 | ETouch Systems SamePage Enterprise Edition SQL注入漏洞 | |
| CVE-2015-0240 | Samba 代码问题漏洞 | |
| CVE-2015-1881 | OpenStack Image Registry and Delivery Service 资源管理错误漏洞 | |
| CVE-2015-1605 | Dell ScriptLogic Asset Manager SQL注入漏洞 | |
| CVE-2015-1572 | e2fsprogs libext2fs库基于堆的缓冲区溢出漏洞 | |
| CVE-2015-0555 | Samsung iPOLiS Device Manager 缓冲区溢出漏洞 | |
| CVE-2014-9684 | OpenStack Image Registry and Delivery Service 资源管理错误漏洞 | |
| CVE-2014-9402 | GNU C Library 资源管理错误漏洞 | |
| CVE-2014-8487 | Kony Management 信息泄露漏洞 | |
| CVE-2013-7423 | GNU C Library 代码注入漏洞 | |
| CVE-2015-2071 | ETouch Systems SamePage Enterprise Edition 目录遍历漏洞 | |
| CVE-2015-2077 | Komodia SDK for Komodia Redirector with SSL Digestor 信息泄露漏洞 | |
| CVE-2015-2069 | WordPress WooCommerce插件跨站脚本漏洞 | |
| CVE-2015-2068 | Magento Server MAGMI插件跨站脚本漏洞 | |
| CVE-2015-2066 | DLGuard SQL注入漏洞 | |
| CVE-2015-2065 | WordPress Apptha WordPress Video Gallery插件SQL注入漏洞 | |
| CVE-2015-2064 | DLGuard 跨站脚本漏洞 | |
| CVE-2014-9282 | Android Speed Root Explorer和Android Speed Explorer应用程序目录遍历漏洞 | |
| CVE-2014-6115 | IBM Rational Insight 信息泄露漏洞 | |
| CVE-2014-4818 | IBM Tivoli Storage Manager dsmtca程序信息泄露漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet