CVE-2015-1397
Magento eCommerce - Remote Code Execution
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
5
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.
Vulnerabilidad de inyección SQL en la función getCsvFile en la clase Mage_Adminhtml_Block_Widget_Grid en Magento Community Edition (CE) 1.9.1.0 y Enterprise Edition (EE) 1.14.1.0 permite a administradores remotos ejecutar comandos SQL arbitrarios a través del parámetro popularity[field_expr] cuando el parámetro popularity[from] o popularity[to] está configurado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-01-27 CVE Reserved
- 2015-04-29 CVE Published
- 2015-08-26 First Exploit
- 2024-07-13 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability | X_refsource_misc | |
http://www.securitytracker.com/id/1032194 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/37977 | 2015-08-26 | |
https://github.com/tmatejicek/CVE-2015-1397 | 2022-04-07 | |
https://github.com/WHOISshuvam/CVE-2015-1397 | 2024-05-18 | |
https://github.com/Wytchwulf/CVE-2015-1397-Magento-Shoplift | 2024-07-19 | |
https://blog.sucuri.net/2015/04/magento-shoplift-supee-5344-exploits-in-the-wild.html | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 1.9.1.0 Search vendor "Magento" for product "Magento" and version "1.9.1.0" | community |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 1.14.1.0 Search vendor "Magento" for product "Magento" and version "1.14.1.0" | enterprise |
Affected
|