CVE-2007-2070
SunShop Shopping Cart < 3.5.1 - Remote Code Execution via abs_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2070. PoCs published by irvian.
AI-analyzed exploit summary The code describes a Remote File Include (RFI) vulnerability in SunShop v3.5, where the 'abs_path' parameter in index.php and checkout.php can be manipulated to include arbitrary remote files. No actual exploit code is provided, only a description of the vulnerability and exploitation method.
Description
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.
Exploits (1)
The code describes a Remote File Include (RFI) vulnerability in SunShop v3.5, where the 'abs_path' parameter in index.php and checkout.php can be manipulated to include arbitrary remote files. No actual exploit code is provided, only a description of the vulnerability and exploitation method.