HIGH
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070
Published May 2, 2007
7.5
HIGHCVSS 2.0
EPSS 6.16%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.