Collected research
HikaShop Object Injection
Deep Dive into the HikaShop Vulnerability
The Joomla HikaShop extension passed base64-decoded user input straight to unserialize, allowing PHP object injection. Sucuri chains JDatabaseDriverMysqli's destructor into PHPMailer's sendmail path and abuses sendmail's queue and log options to write the outgoing mail, whose subject carries PHP code, into a file under the web root, turning the injection into a backdoor.
Record
- Document
- Deep Dive into the HikaShop Vulnerability
- Published by
- Sucuri Blog
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sucuri Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .