CVE-2007-4933 Information

Description

Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php as demonstrated with the (1) productscount (2) colscount and (3) darkcolor parameters.

Reference

http://secunia.com/advisories/26840 http://www.securityfocus.com/bid/25695 https://www.exploit-db.com/exploits/4419

Share on: