7.5
CVSSv2

CVE-2007-4933

Published: 18/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and previous versions allows remote malicious users to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shop-script shop-script 2.0

Exploits

<?php ## Shop-Script FREE <= 20 Remote Command Execution Exploit by InATeam ## tested on versions 12 and 20 ## works regardless magic_quotes_gpc=on ## Greetz: eXp, Kuzya, cxim, Russian, ENFIX echo "--------------------------------------------------------\n"; echo "Shop-Script FREE <= 20 Remote Command Execution Exploit\n"; echo "(c)od ...