exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 52 RSS Feed

Files

Magento 2.4.6 XSLT Server Side Injection
Posted Nov 20, 2023
Authored by tmrswrr

Magento version 2.4.6 XSLT server-side injection proof of concept exploit.

tags | exploit, proof of concept
SHA-256 | ae81950e2fc15cf464a8175e05b574b8b5b2ed4aba982fabb1e7d86affd1d181

Related Files

FireBear Improved Import And Export 3.8.6 XSLT Server Side Injection
Posted Nov 20, 2023
Authored by tmrswrr

FireBear Improved Import and Export version 3.8.6 for Magento 2.4.6 suffers from an XSLT server-side injection vulnerability that allows for command execution.

tags | exploit
SHA-256 | df34e619c87b7e586946acac49e63f30ac9fb2932315a44429238bc3e51eb867
Magento 2.4.6 XSLT Server Side Injection / Command Execution
Posted Nov 17, 2023
Authored by tmrswrr

Magento version 2.4.6 suffers from an XSLT server side injection vulnerability that allows for remote command execution.

tags | exploit, remote
SHA-256 | f9be4bd2cd3a935d1b1911f4dc66750b1b4e10e9f0e0a5d9921fedffe77d7f52
Magento eCommerce 2.4.0 Information Disclosure
Posted Jun 7, 2023
Authored by indoushka

Magento eCommerce version 2.4.0 suffers from an information disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | ab3ecd35ea1bd5ea43f71e8cc7229f70824a190697fc616d9688716fd6a524a1
Magento eCommerce CE 2.3.5-p2 SQL Injection
Posted May 11, 2022
Authored by Aydin Naserifard

Magento eCommerce CE version 2.3.5-p2 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 6bd20eca04da6895841882a1873693c9a525676db72c5667f0148e99e19eaeb3
Adobe Magento Commerce Cross Site Scripting
Posted Feb 10, 2021
Authored by Natsasit Jirathammanuwat | Site sec-consult.com

Adobe Magento Commerce versions prior to 2.4.2 suffer from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2021-21029
SHA-256 | 901c1af1587ebc9a26b154995ec271cad02931488eb9cef602e6b0bd29fa4817
Magento WooCommerce CardGate Payment Gateway 2.0.30 Bypass
Posted Feb 25, 2020
Authored by GeekHack

Magento WooCommerce CardGate Payment Gateway version 2.0.30 suffers from a payment process bypass vulnerability.

tags | exploit, bypass
advisories | CVE-2020-8818
SHA-256 | faccc20610a3a485e40c8340014f14252b181308de06bde1189b8099b5152e83
Magento 2.3.0 SQL Injection
Posted Mar 29, 2019
Authored by Charles FOL

Magento versions 2.2.0 through 2.3.0 unauthenticated remote SQL injection exploit.

tags | exploit, remote, sql injection
SHA-256 | fb8e5118d988e50510319ef6725fac056f280cc00faa123b19459e9412e70b6b
Magento Product Attributes Cross Site Scripting
Posted Mar 6, 2018
Authored by DefenseCode, Bosko Stankovic

Magento suffers from product attribute information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

tags | exploit, vulnerability, xss
SHA-256 | 549e235e03ef0bdbe9eea05a3e1bd3f340f29761c9abdad73f4036142c0591e3
Magento Downloadable Products Cross Site Scripting
Posted Mar 6, 2018
Authored by DefenseCode, Bosko Stankovic

Magento suffers from downloadable product information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

tags | exploit, vulnerability, xss
SHA-256 | 1bbd2c7b993ffcb1a4ef9c205272274661f6065ff4e313cd2057ced8ea75d918
Magento Backups Cross Site Request Forgery
Posted Mar 6, 2018
Authored by DefenseCode, Bosko Stankovic

Magento Backups suffer from a cross site request forgery vulnerability. Versions affected include Magento Open Source prior to 1.9.3.8, Magento Commerce prior to 1.14.3.8, Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

tags | exploit, csrf
SHA-256 | 6d870f518782a4d674caa1e656efd73fa25831cbd1426facfd575d0b2defcd72
Magento User Info Cross Site Scripting
Posted Mar 6, 2018
Authored by DefenseCode, Bosko Stankovic

Magento suffers from user information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

tags | exploit, vulnerability, xss
SHA-256 | 8655d134ed2747f6351bd7d013f6487b55c2509759a2cba576f6d2143f46f59d
Magento Commerce Server-Side Request Forgery
Posted Jan 12, 2018
Authored by Vulnerability Laboratory | Site vulnerability-lab.com

Magento Commerce suffers from a server-side request forgery vulnerability.

tags | exploit
SHA-256 | 1b97b6d0217df01399ed249baa6ccf75d4e0bcb15c924c8dab1f85d9a963a2f3
Magento Connect T1 Cross Site Scripting
Posted Jan 12, 2018
Authored by Vulnerability Laboratory | Site vulnerability-lab.com

Magento Connect T1 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 9dd4f20451076e82d19e763c373999dc1a6852006efc110285863089e2fe1674
Magento Cross Site Requst Forgery / Cross Site Scripting
Posted Oct 5, 2017
Authored by DefenseCode, Bosko Stankovic

During a security audit of Magento Community Edition / Open Source and Commerce, cross site request forgery and stored cross site scripting vulnerabilities were discovered that could lead to administrator account takeover, putting the website customers and their payment information at risk. Versions affected include Magento CE 1 prior to 1.9.3.6, Magento Commerce prior to 1.14.3.6, Magento 2.0 prior to 2.0.16, and Magento 2.1 prior to 2.1.9.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 4d32bf78790a47b612f73e6f5369bdb54efc47178d31a6a5c2caee2287e9d34f
Magento Cross Site Requst Forgery / Cross Site Scripting
Posted Oct 4, 2017
Authored by DefenseCode, Bosko Stankovic

During a security audit of Magento Community Edition / Open Source and Commerce, cross site request forgery and stored cross site scripting vulnerabilities were discovered that could lead to administrator account takeover, putting the website customers and their payment information at risk. This is a second advisory from DefenseCode for the same software and vulnerabilities. Versions affected include Magento CE 1 prior to 1.9.3.6, Magento Commerce prior to 1.14.3.6, Magento 2.0 prior to 2.0.16, and Magento 2.1 prior to 2.1.9.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 8d86ea8e9eb75bb36c388fcd274b7cd6fb4431c98f0098e80d1cb745bb4f4af9
Magento 2.1.6 Shell Upload / Cross Site Request Forgery
Posted Apr 13, 2017
Authored by DefenseCode, Bosko Stankovic

Magento versions 2.1.6 and below suffers from cross site request forgery and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, csrf
SHA-256 | ec3736ddab1c899309a6378effc0830e101ad19846971bb0f43a9f8c173055b2
Magento Bruteforcer
Posted Nov 20, 2016
Authored by Goudini

This is a piece of software that tries to login to Magento administrative panels using a list of websites, logins, and passwords. Written in C++.

tags | tool, scanner
systems | unix
SHA-256 | 084ff1803c63eac0a6875fa94140fee427f36799ed0e2a39ee9a4fa8c565d48c
Magento 2.0.6 Unserialize Remote Code Execution
Posted Jun 3, 2016
Authored by agix, Netanel Rubin | Site metasploit.com

This Metasploit module exploits a PHP object injection vulnerability in Magento 2.0.6 or prior.

tags | exploit, php
advisories | CVE-2016-4010
SHA-256 | 0f4a54fd7327964f36b2aa61027c88bb06c66470231cb05fee46900549f0def5
Magento Unauthenticated Arbitrary File Write
Posted May 18, 2016
Authored by agix

Magento versions prior to 2.0.6 suffer from an unauthenticated arbitrary unserialize to arbitrary write file vulnerability.

tags | exploit, arbitrary
advisories | CVE-2016-4010
SHA-256 | aabdfe5b303d6f19ce1fc498c50679f141c6beebfcd6c15c192c8f28b94a86a8
Magento 1.9.2.2 RSS Feed Information Disclosure
Posted Feb 25, 2016
Authored by EgiX

Magento versions 1.9.2.2 and below suffer from an information disclosure vulnerability in their RSS feed.

tags | exploit, info disclosure
advisories | CVE-2016-2212
SHA-256 | 01b433ea9ea8a8bfd60a02085deff0d6671bc1935cc0aafe2a78128162522f37
eBay Magento Persistent Mail Encoding
Posted Jan 28, 2016
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

eBay Magento suffered from a persistent mail encoding vulnerability.

tags | exploit
SHA-256 | 1f7e3c4c0d1e24a790c770bc054c59941b6b14c695d15033a678f7bdd0ccdf23
Magento 1.9.x Man-In-The-Middle
Posted Jan 26, 2016
Authored by Maksymilian Arciemowicz

Magento versions 1.9.x suffer from a man-in-the-middle vulnerability.

tags | advisory
SHA-256 | 1a8ec89508ab76d3e1690d5c566a439a7120f88d7945d716564e509ba86b8747
Ebay Magento Cross Site Request Forgery
Posted Nov 17, 2015
Authored by Hadji Samir, Vulnerability Laboratory | Site vulnerability-lab.com

Ebay Magento suffered from multiple cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
SHA-256 | 9100b8e6174a98fe814cca49771a623e8ed97ea3ca97aba563a8cdfb93846e04
Ebay Magento Commerce Cross Site Scripting
Posted Nov 17, 2015
Authored by Hadji Samir, Vulnerability Laboratory | Site vulnerability-lab.com

Ebay Magento Commerce suffered from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | d053d31a2e30a77f10b17da4ec3786d918f2e3f72ec4c69bda9bb8bedc20b230
eBay Magento XXE Injection
Posted Oct 30, 2015
Authored by Dawid Golunski

eBay Magento CE versions 1.9.2.1 and below and eBay Magento EE versions 1.14.2.1 and below suffer from an XXE injection vulnerability.

tags | exploit, xxe
SHA-256 | 08393363d6670e33368d62daac52944168d2958ae3fd00c5baedaa4999a731b3
Page 1 of 3
Back123Next

File Archive:

December 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    0 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    32 Files
  • 5
    Dec 5th
    10 Files
  • 6
    Dec 6th
    13 Files
  • 7
    Dec 7th
    23 Files
  • 8
    Dec 8th
    19 Files
  • 9
    Dec 9th
    1 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close