CVE-2007-1127
shopkitplus - Directory Traversal via changetheme Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1127. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in Shop Kit Plus, where unsanitized user input allows directory traversal to access sensitive files like /etc/passwd. No actual exploit code is present, only a description and example URL.
Description
Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.
Exploits (1)
The provided text describes a local file inclusion (LFI) vulnerability in Shop Kit Plus, where unsanitized user input allows directory traversal to access sensitive files like /etc/passwd. No actual exploit code is present, only a description and example URL.