HTTP: Magento API unserialize Remote Code Execution

A remote code execution vulnerability exists in the eCommerce platform Magento. Successful exploitation allows the attacker to write to arbitrary files.

Extended Description

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

Affected Products

Magento magento

Short Name
HTTP:CGI:MAGENTO-API-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
API CVE-2016-4010 Code Execution Magento Remote unserialize
Release Date
06/09/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Magento

CVSS Score

7.5

Found a potential security threat?