VYPR

Magento

by Magento

Source repositories

CVEs (227)

  • CVE-2015-1397Apr 29, 2015
    risk 0.08cvss —epss 0.52

    SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr]…

  • CVE-2009-0541Feb 25, 2009
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the…

  • CVE-2015-3457Apr 29, 2015
    risk 0.02cvss —epss 0.25

    Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

  • CVE-2015-1399Apr 29, 2015
    risk 0.01cvss —epss 0.10

    PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via a URL in unspecified vectors…

  • CVE-2015-1398Apr 29, 2015
    risk 0.01cvss —epss 0.14

    Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. (dot dot) sequences in the PATH_INFO to index.php or (2) vectors…

  • CVE-2015-3458Apr 29, 2015
    risk 0.00cvss —epss 0.06

    The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a template path, which allows remote administrators to include and execute arbitrary PHP…

  • CVE-2011-5240Nov 6, 2012
    risk 0.00cvss —epss 0.01

    Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Page 12 of 12