CVE-2016-4010 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 92.9% (pctl 100)
Patch early
A public exploit exists.
Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.87% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-01-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| magento | magento |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File | 2016-05-18 |
References
- http://netanelrub.in/2016/05/17/magento-unauthenticated-remote-code-execution/
- https://magento.com/security/patches/magento-206-security-update
- https://packetstormsecurity.com/files/137121/Magento-Unauthenticated-Arbitrary-File-Write.html
- https://packetstormsecurity.com/files/137312/Magento-2.0.6-Unserialize-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/39838/
- http://netanelrub.in/2016/05/17/magento-unauthenticated-remote-code-execution/
- https://magento.com/security/patches/magento-206-security-update
- https://packetstormsecurity.com/files/137121/Magento-Unauthenticated-Arbitrary-File-Write.html
- https://packetstormsecurity.com/files/137312/Magento-2.0.6-Unserialize-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/39838/
→ the Explorer · watch your stack · NVD