Magento Open Source是提供基本的电子商务功能,允许您从头开始构建独特的在线商店。Magento Commerce是提供一流的购物体验,而无需开发人员的支持。 Magento Commerce 和 Magento Open Source存在操作系统命令注入漏洞,该漏洞的存在是由于处理XML数据时不正确的输入验证。远程管理员可以向应用程序传递特制的XML数据,并在系统上执行任意操作。该漏洞允许远程用户在目标系统上执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Adobe Commerce | 0 ~ 2.3.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21088 | 7.8 HIGH | Adobe Acrobat Pro DC Use-After-Free Remote Code Execution Vulnerability |
| CVE-2021-35980 | 7.8 HIGH | Adobe Acrobat Reader SpellDictionaryExport Path Traversal Remote Code Execution Vulnerabil |
| CVE-2021-28644 | 7.8 HIGH | Adobe Acrobat SpellDictionaryCreate Path Traversal Remote Code Execution Vulnerability |
| CVE-2021-36036 | 7.2 HIGH | Magento Commerce Media Gallery Upload Improper Access Control Could Lead To Remote Code Ex |
| CVE-2021-36021 | 7.2 HIGH | Magento Commerce CMS Page Improper Input Validation Could Lead To Remote Code Execution |
| CVE-2021-39859 | 5.5 MEDIUM | Use After Free Adobe Acrobat Pro DC [HB-21-0339] |
| CVE-2021-36060 | 5.5 MEDIUM | Adobe Media Encoder MPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabil |
No comments yet