CVE-2006-4904
Qualiteam X-Cart < 4.1.3 - Remote Code Execution via cmpi.php Dynamic Variable Evaluation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4904. PoCs published by GulfTech Security.
AI-analyzed exploit summary The exploit describes an arbitrary variable overwrite vulnerability in X-Cart's cmpi.php script, allowing attackers to execute arbitrary PHP code by manipulating POST variables. The vulnerability stems from insecure dynamic variable assignment without validation.
Description
Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir parameter.
Exploits (1)
The exploit describes an arbitrary variable overwrite vulnerability in X-Cart's cmpi.php script, allowing attackers to execute arbitrary PHP code by manipulating POST variables. The vulnerability stems from insecure dynamic variable assignment without validation.