7.5
CVSSv2

CVE-2007-2070

Published: 18/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart prior to 3.5.1 allow remote malicious users to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

Vulnerable Product Search on Vulmon Subscribe to Product

turnkey web tools sunshop shopping cart 3.5

turnkey web tools sunshop shopping cart

Exploits

sunshop 4 (indexphp) Remote File Include Vulnerability ----------------------------------------------------------------------------------------- # scripts : SunShop v35 # Discovered By : irvian # scripts site : wwwturnkeywebtoolscom/sunshop/ # Thanks To : #hitamputih #nyubicrew #patihack # special To : nyubi,ibnusina,arioo ...