PT-2007-5620 · Squirrelcart · Squirrelcart
Shai Magal
·
Publicado
2007-08-21
·
Atualizado
2017-09-29
·
CVE-2007-4439
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squirrelcart versions 1.x.x and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
site isp root parameter, probably related to cart.php. This can be exploited by providing a malicious URL to the vulnerable parameter, potentially leading to the execution of arbitrary code.Recommendations
For Squirrelcart versions 1.x.x and earlier, restrict access to the
popup window.php file and avoid using the site isp root parameter until a fix is available. As a temporary workaround, consider validating and sanitizing all input to the site isp root parameter to prevent malicious URLs from being executed.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Squirrelcart