PT-2007-5620 · Squirrelcart · Squirrelcart

Shai Magal

·

Publicado

2007-08-21

·

Atualizado

2017-09-29

·

CVE-2007-4439

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squirrelcart versions 1.x.x and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the site isp root parameter, probably related to cart.php. This can be exploited by providing a malicious URL to the vulnerable parameter, potentially leading to the execution of arbitrary code.
Recommendations For Squirrelcart versions 1.x.x and earlier, restrict access to the popup window.php file and avoid using the site isp root parameter until a fix is available. As a temporary workaround, consider validating and sanitizing all input to the site isp root parameter to prevent malicious URLs from being executed.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4439

Produtos afetados

Squirrelcart