Magento / Adobe Commerce Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 19 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module uses a combination of an arbitrary file read (CVE-2024-34102) and a buffer overflow in glibc (CVE-2024-2961). It allows for unauthenticated remote code execution on various versions of Magento and Adobe Commerce (and earlier versions if the PHP and glibc versions are also vulnerable). Versions affected include 2.4.7 and earlier, 2.4.6-p5 and earlier, 2.4.5-p7 and earlier, and 2.4.4-p8 and earlier.

    Continue reading...
     

Share This Page

Loading...