PT-2007-5620 · Squirrelcart · Squirrelcart
Shai Magal
·
Published
2007-08-21
·
Updated
2017-09-29
·
CVE-2007-4439
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squirrelcart versions 1.x.x and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
site isp root parameter, probably related to cart.php. This can be exploited by providing a malicious URL to the vulnerable parameter, potentially leading to the execution of arbitrary code.Recommendations
For Squirrelcart versions 1.x.x and earlier, restrict access to the
popup window.php file and avoid using the site isp root parameter until a fix is available. As a temporary workaround, consider validating and sanitizing all input to the site isp root parameter to prevent malicious URLs from being executed.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squirrelcart