CVE-2007-3936
a-shop < 0.70 - Path Traversal and Arbitrary File Deletion via filebrowser.asp delfiles Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3936. PoCs published by Timq.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file deletion vulnerability in A-shop <=0.70 via a crafted HTTP request to 'filebrowser.asp'. It also mentions SQL injection vulnerabilities in other areas but does not provide specific details.
Description
Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filename references in the delfiles parameter.
Exploits (1)
The exploit demonstrates an arbitrary file deletion vulnerability in A-shop <=0.70 via a crafted HTTP request to 'filebrowser.asp'. It also mentions SQL injection vulnerabilities in other areas but does not provide specific details.