Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-1397 PoC — Magento Community Edition和Enterprise Edition SQL注入漏洞

Source
Associated Vulnerability
Title:Magento Community Edition和Enterprise Edition SQL注入漏洞 (CVE-2015-1397)
Description:SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.
File Snapshot

[4.0K] /data/pocs/36d0ecdc6bd797737f39b5ce4b6bc207fdc8da6c └── [1.1K] CVE-2015-1397.ps1 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →