{"api_version":"1","generated_at":"2026-07-23T08:43:06+00:00","cve":"CVE-2015-6497","urls":{"html":"https://cve.report/CVE-2015-6497","api":"https://cve.report/api/cve/CVE-2015-6497.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-6497","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-6497"},"summary":{"title":"CVE-2015-6497","description":"The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-15 17:15:00","updated_at":"2020-01-22 16:22:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"http://karmainsecurity.com/KIS-2015-04","name":"http://karmainsecurity.com/KIS-2015-04","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Magento <= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability | Karma(In)Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2015/Sep/48","name":"http://seclists.org/fulldisclosure/2015/Sep/48","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: [KIS-2015-04] Magento <= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://magento.com/security/patches/supee-6482","name":"http://magento.com/security/patches/supee-6482","refsource":"MISC","tags":["Vendor Advisory"],"title":"SUPEE-6482 | Magento","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.mindedsecurity.com/2015/09/autoloaded-file-inclusion-in-magento.html","name":"http://blog.mindedsecurity.com/2015/09/autoloaded-file-inclusion-in-magento.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Minded Security Blog: Autoloaded File Inclusion in Magento SOAP API (SUPEE-6482)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/133544/Magento-1.9.2-File-Inclusion.html","name":"http://packetstormsecurity.com/files/133544/Magento-1.9.2-File-Inclusion.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Magento 1.9.2 File Inclusion ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-6497","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-6497","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"6497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6497","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6497","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2015-6497","qid":"996608","title":"PHP (Composer) Security Update for magento/core (GHSA-j4fq-3fm7-wh5v)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-6497","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"references":{"reference_data":[{"refsource":"MISC","name":"http://packetstormsecurity.com/files/133544/Magento-1.9.2-File-Inclusion.html","url":"http://packetstormsecurity.com/files/133544/Magento-1.9.2-File-Inclusion.html"},{"refsource":"MISC","name":"http://blog.mindedsecurity.com/2015/09/autoloaded-file-inclusion-in-magento.html","url":"http://blog.mindedsecurity.com/2015/09/autoloaded-file-inclusion-in-magento.html"},{"refsource":"MISC","name":"http://karmainsecurity.com/KIS-2015-04","url":"http://karmainsecurity.com/KIS-2015-04"},{"refsource":"MISC","name":"http://seclists.org/fulldisclosure/2015/Sep/48","url":"http://seclists.org/fulldisclosure/2015/Sep/48"},{"refsource":"MISC","name":"http://magento.com/security/patches/supee-6482","url":"http://magento.com/security/patches/supee-6482"}]}},"nvd":{"publishedDate":"2020-01-15 17:15:00","lastModifiedDate":"2020-01-22 16:22:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:community:*:*:*","versionEndExcluding":"1.9.2.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"1.14.2.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.24","cpe_name":[]},{"vulnerable":false,"cpe23Uri":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.25","versionEndExcluding":"5.5.8","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"6497","Ordinal":"83498","Title":"CVE-2015-6497","CVE":"CVE-2015-6497","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"6497","Ordinal":"1","NoteData":"The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"6497","Ordinal":"2","NoteData":"2020-01-15","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"6497","Ordinal":"3","NoteData":"2020-01-15","Type":"Other","Title":"Modified"}]}}}