CVE-2015-1399
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via a URL in unspecified vectors involving the setScriptPath function. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have privileges to include arbitrary files.
Vulnerabilidad de la inclusión remota de ficheros PHP en la función fetchView en la clase Mage_Core_Block_Template_Zend en Magento Community Edition (CE) 1.9.1.0 y Enterprise Edition (EE) 1.14.1.0 permite a administradores remotos ejecutar código PHP arbitrario a través de una URL en vectores no especificados que involucran la función setScriptPath. NOTA: no está claro si este problema cruza los límites de privilegios, como los administradores podrían ya tener los privilegios para incluir ficheros arbitrarios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-27 CVE Reserved
- 2015-04-29 CVE Published
- 2024-02-17 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1032194 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://magento.com/blog/technical/critical-security-advisory-remote-code-execution-rce-vulnerability | 2016-04-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 1.9.1.0 Search vendor "Magento" for product "Magento" and version "1.9.1.0" | community |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 1.14.1.0 Search vendor "Magento" for product "Magento" and version "1.14.1.0" | enterprise |
Affected
|