vendor:
Magento
by:
Manish Kishan Tanwar AKA error1046
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Magento
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Magento Shoplift exploit (SUPEE-5344)
Magento shoplift bug originally discovered by CheckPoint team (http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability/). This python script developed by joren but it was having some bug because of which it was not working properly. If magento version is vulnerable, this script will create admin account with username forme and password forme.
Mitigation:
Upgrade to the latest version of Magento to patch the vulnerability.