CVE-2016-3109: Input Validation
Published Apr 8, 2016
·Updated
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
Other sources
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
Unauthenticated Remote Code Execution Vulnerability
Affected Software
4 affected componentsFixes available
composer/shopware/shopware<4.3.7, >=5.0.0, <5.1.0, >=5.1.0, <5.1.5
composer/shopware/shopware>=5.0.0<5.1.5
5.1.5
composer/shopware/shopware<4.3.7
4.3.7
Shopware Shopware<=5.1.4
Remediation
Event History
Apr 8, 2016
Advisory Published
08:54 AM
Apr 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3109?
CVE-2016-3109 is rated as a high severity vulnerability due to its potential to allow unauthenticated remote code execution.
2
How do I fix CVE-2016-3109?
To fix CVE-2016-3109, upgrade Shopware to version 5.1.5 or later, or to version 4.3.7.
3
Who is affected by CVE-2016-3109?
CVE-2016-3109 affects Shopware versions before 5.1.5, specifically those in the 4.x and 5.0.x branches.
4
What type of vulnerability is CVE-2016-3109?
CVE-2016-3109 is classified as an unauthenticated remote code execution vulnerability.
5
Can CVE-2016-3109 be exploited remotely?
Yes, CVE-2016-3109 can be exploited remotely by attackers without authentication.