CVE-2015-6497
Summary
| CVE | CVE-2015-6497 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-15 17:15:00 UTC |
| Updated | 2020-01-22 16:22:00 UTC |
| Description | The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Magento <= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability | Karma(In)Security | MISC | karmainsecurity.com | Exploit, Third Party Advisory |
| Full Disclosure: [KIS-2015-04] Magento <= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| SUPEE-6482 | Magento | MISC | magento.com | Vendor Advisory |
| Minded Security Blog: Autoloaded File Inclusion in Magento SOAP API (SUPEE-6482) | MISC | blog.mindedsecurity.com | Exploit, Third Party Advisory |
| Magento 1.9.2 File Inclusion ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996608 PHP (Composer) Security Update for magento/core (GHSA-j4fq-3fm7-wh5v)