Vulnerabilities > CVE-2007-2474 - Remote File Include vulnerability in TurnkeyWebTools Sunshop

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
turnkey-web-tools
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.

Vulnerable Configurations

Part Description Count
Application
Turnkey_Web_Tools
1

Exploit-Db

descriptionTurnkeyWebTools Sunshop 3.5/4.0 Multiple Remote File Include Vulnerabilities. CVE-2007-2474 . Webapps exploit for php platform
idEDB-ID:29908
last seen2016-02-03
modified2007-04-25
published2007-04-25
reporters3rv3r_hack3r
sourcehttps://www.exploit-db.com/download/29908/
titleTurnkeyWebTools Sunshop 3.5/4.0 - Multiple Remote File Include Vulnerabilities