As many as 200,000 websites use Magento e-commerce platform, which is owned by eBay.

The exploit code Sucuri analyzed is a SQL injection attack, which inserts a new admin_user into a database.

Cid wrote the exploit uses the usernames vpwq and defaultmanager.

Hackers exploit Zero day Magento e-commerce vulnerability to steal credit card details

The presence of those names on a system could indicate a successful attack.

spot_img

source: www.techworm.net