Showing posts with label Magento. Show all posts
Showing posts with label Magento. Show all posts

Monday, 31 August 2015

Remote Code Execution 0day

Hi Friends,

Many of you already know that people try to do the things which provide them some fruits. likewise Carders trying to Exploit Shopping carts for getting into the transaction system in order to snatch people's money. Magento is a famous eCommerce CMS. this is the main target also as many of shopping sites are based on this CMS.

Here is a Recent exploit "obviously not found by me but code is mine." Which allows an attacker to change Username and Password of a site remotely. this is due to remote code Execution.

Exploit Code



and here are Results i got from Execution of the Script.



Bingoo !!


P.S: No any sites were harmed and Affected ones are reported already.


References:

  • http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability/


Magento Shopping Cart 0day Exploit

By: Adeel Chaudhary on: 02:13

 
Copyright © HACK | Designed by Muhammad Adeel | Founder UrduSecurity