PT-2007-6751 · Caupo · Cauposhop Pro

Mozi

·

Published

2007-11-01

·

Updated

2017-09-29

·

CVE-2007-5784

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CaupoShop Pro versions 2.x
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the action parameter in the index.php file. This can be exploited by sending a malicious URL to the vulnerable endpoint.
Recommendations For CaupoShop Pro versions 2.x, consider restricting access to the index.php file or disabling the action parameter until a patch is available. Avoid using the action parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5784

Affected Products

Cauposhop Pro