Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4597. PoCs published by k1tk4t.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in SunShop v4.0 RC 6 by injecting malicious SQL code into the 's[cid]' parameter. It brute-forces character extraction from the database to retrieve admin credentials.
Description
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in SunShop v4.0 RC 6 by injecting malicious SQL code into the 's[cid]' parameter. It brute-forces character extraction from the database to retrieve admin credentials.