CVE-2007-2070

SunShop Shopping Cart < 3.5.1 - Remote Code Execution via abs_path Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2070. PoCs published by irvian.

AI-analyzed exploit summary The code describes a Remote File Include (RFI) vulnerability in SunShop v3.5, where the 'abs_path' parameter in index.php and checkout.php can be manipulated to include arbitrary remote files. No actual exploit code is provided, only a description of the vulnerability and exploitation method.

Description

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by irvian · textwebappsphp
https://www.exploit-db.com/exploits/3748

The code describes a Remote File Include (RFI) vulnerability in SunShop v3.5, where the 'abs_path' parameter in index.php and checkout.php can be manipulated to include arbitrary remote files. No actual exploit code is provided, only a description of the vulnerability and exploitation method.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: SunShop v3.5
No auth needed
Prerequisites: Remote file inclusion must be enabled on the target server · Attacker must have access to a remote server hosting malicious code
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37415
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37414
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1422
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3748
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33670
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23511

Scores

EPSS 0.0942
EPSS Percentile 94.8%

Details

CWE
CWE-94
Status published
Products (2)
turnkey_web_tools/sunshop_shopping_cart 3.5
turnkey_web_tools/sunshop_shopping_cart < 4.0
Published Apr 18, 2007
Tracked Since Feb 18, 2026