CVE-2007-4925
eWire Payment Client 1.60 and 1.70 - Remote Command Execution via PaymentInfo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4925. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in ewire Payment Client versions 1.60 and 1.70. The vulnerability allows arbitrary shell command execution via unsanitized input in the 'paymentinfo' parameter, leading to remote code execution (RCE) with the privileges of the web server.
Description
The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.
Exploits (1)
This exploit demonstrates a command injection vulnerability in ewire Payment Client versions 1.60 and 1.70. The vulnerability allows arbitrary shell command execution via unsanitized input in the 'paymentinfo' parameter, leading to remote code execution (RCE) with the privileges of the web server.