PT-2007-5620 · Squirrelcart · Squirrelcart

Shai Magal

·

Published

2007-08-21

·

Updated

2017-09-29

·

CVE-2007-4439

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squirrelcart versions 1.x.x and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the site isp root parameter, probably related to cart.php. This can be exploited by providing a malicious URL to the vulnerable parameter, potentially leading to the execution of arbitrary code.
Recommendations For Squirrelcart versions 1.x.x and earlier, restrict access to the popup window.php file and avoid using the site isp root parameter until a fix is available. As a temporary workaround, consider validating and sanitizing all input to the site isp root parameter to prevent malicious URLs from being executed.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4439

Affected Products

Squirrelcart