EIP-2026-100902
PRE-CVEStockman Shopping Cart 7.8 - Arbitrary Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100902. PoCs published by Aleksey Sintsov.
AI-analyzed exploit summary This Perl script exploits a remote command execution vulnerability in Stockman Shopping Cart by injecting commands via the 'page' parameter in the 'shop.plx' script. It establishes a connection to the target, sends crafted HTTP requests, and spawns a bash-style shell with web server privileges.
Description
Stockman Shopping Cart 7.8 - Arbitrary Command Execution
Exploits (1)
This Perl script exploits a remote command execution vulnerability in Stockman Shopping Cart by injecting commands via the 'page' parameter in the 'shop.plx' script. It establishes a connection to the target, sends crafted HTTP requests, and spawns a bash-style shell with web server privileges.