7.5
CVSSv2

CVE-2007-4932

Published: 18/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin.php in Shop-Script FREE 2.0 and previous versions sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote malicious users to access the admin panel.

Vulnerable Product Search on Vulmon Subscribe to Product

shop-script shop-script

Exploits

<?php ## Shop-Script FREE <= 20 Remote Command Execution Exploit by InATeam ## tested on versions 12 and 20 ## works regardless magic_quotes_gpc=on ## Greetz: eXp, Kuzya, cxim, Russian, ENFIX echo "--------------------------------------------------------\n"; echo "Shop-Script FREE <= 20 Remote Command Execution Exploit\n"; echo "(c)od ...