Magento SQL Injection Vulnerability

  Severity: CRITICAL
  CVE Identifier: CVE-2015-1397

  DESCRIPTION

SQL injection vulnerability in Magento 1.9.1.0 CE and 1.14.1.0 EE allows remote attackers to execute arbitrary SQL commands.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000608
  Trend Micro Deep Security DPI Rule Name: 1000608 - Generic SQL Injection Prevention

  AFFECTED SOFTWARE AND VERSION

  • Magento