Web Hack List

Other nomination

HikaShop Object Injection

The Joomla HikaShop extension passed base64-decoded user input straight to unserialize, allowing PHP object injection. Sucuri chains JDatabaseDriverMysqli's destructor into PHPMailer's sendmail path and abuses sendmail's queue and log options to write the outgoing mail, whose subject carries PHP code, into a file under the web root, turning the injection into a backdoor.

Record

Published by
Sucuri Blog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sucuri Blog, first published at the original source. Preserved copies are kept so the citation survives its host.