CVE-2007-2424
The Merchant 2.2 - Remote File Inclusion via help/index.php show Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2424. PoCs published by kezzap66345.
AI-analyzed exploit summary This is a client-side HTML/JavaScript exploit for a remote file inclusion (RFI) vulnerability in The Merchant Project. It constructs a malicious URL to include a remote shell script via the 'show' parameter in index.php.
Description
PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter.
Exploits (1)
This is a client-side HTML/JavaScript exploit for a remote file inclusion (RFI) vulnerability in The Merchant Project. It constructs a malicious URL to include a remote shell script via the 'show' parameter in index.php.