{"id":"GHSA-c252-xc8v-mqmm","summary":"MAGMI plugin for Magento Server Directory Traversal","details":"Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.","aliases":["CVE-2015-2067"],"modified":"2024-12-03T06:08:26.730139Z","published":"2022-05-13T01:25:27Z","database_specific":{"github_reviewed_at":"2023-07-31T23:42:03Z","nvd_published_at":"2015-02-24T17:59:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2067"},{"type":"PACKAGE","url":"https://github.com/dweeves/magmi-git"},{"type":"WEB","url":"https://web.archive.org/web/20210122162452/http://www.securityfocus.com/bid/74881"},{"type":"WEB","url":"http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.html"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/35996"}],"affected":[{"package":{"name":"dweeves/magmi","ecosystem":"Packagist","purl":"pkg:composer/dweeves/magmi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.7.21"}]}],"versions":["0.7.19","0.7.19a","0.7.20","0.7.21"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c252-xc8v-mqmm/GHSA-c252-xc8v-mqmm.json"}}],"schema_version":"1.9.0"}