7.5
CVSSv2

CVE-2007-4907

Published: 17/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote malicious users to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and (6) admin/auth.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualiteam x-cart 3.5.0

Exploits

## xCart Remote file inclusion ## ## Download script : wwwx-cartcom// ## Discovered By : aLiiF aka [arif] @debuteam 07/09/2007 ## HomePage : wwwdebuteamnet// ## Thx to : Debu Newbie Payment Yogac nyubi Rozi ^S0n_g0ku^ Kuris Sonix Toxicity newbi3 R4yn4ld0 DisJocKey s3ng0k home_edition Holong home_edition2001 th0nk Scr3W_W0rm ...