Magento

Magento CMS

Scan

> php magescan.phar scan:all 10.x.x.x

Create Admin

  • RCE 37977

  • Magento eCommerce- Remote code Execution-37977.py

  • Will create admin creds using a sql injection

Authenticated RCE 37811

Upload IDE

Froghopper Attack (RCE)

Upload Evil Plugin

  • Requires Admin login

  • MAGento plugins are basically php file zipped.

  • Zip an evil php and upload it as a Plugin

  • Did not work for swagshopHTB

Last updated

Was this helpful?