Limited Black Friday Offer:
Magento Server Magmi Plugin - Cross Site Scripting - XSS Vulnerability CVE-2015-2068 Scanner
Remote attacker can perform a reflected cross site scripting attack (XSS) by injecting malicious payload.
Short Info
Level
Medium
Type
Single Scan
Can be used by
Asset Owner
Estimated Time
10 sec
Scan only one
Url
Parent Category
Magento Server Magmi Plugin - Cross Site Scripting - XSS Vulnerability CVE-2015-2068 Scanner Detail
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.