CVE-2008-2224
SazCart 1.5.1 - Remote Code Execution via PHP File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2224. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in SazCart 1.5.1 due to improper input validation when register_globals is enabled. It allows an attacker to include arbitrary remote files, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _saz[settings][site_dir] parameter to layouts/default/header.saz.php and the (2) _saz[settings][site_url] parameter to admin/alayouts/default/pages/login.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in SazCart 1.5.1 due to improper input validation when register_globals is enabled. It allows an attacker to include arbitrary remote files, potentially leading to remote code execution.