Web Hack List

Collected research

HikaShop Object Injection

Deep Dive into the HikaShop Vulnerability

The Joomla HikaShop extension passed base64-decoded user input straight to unserialize, allowing PHP object injection. Sucuri chains JDatabaseDriverMysqli's destructor into PHPMailer's sendmail path and abuses sendmail's queue and log options to write the outgoing mail, whose subject carries PHP code, into a file under the web root, turning the injection into a backdoor.

Record

Document
Deep Dive into the HikaShop Vulnerability
Published by
Sucuri Blog
Date
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sucuri Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .