CVE-2005-4787
published 2005-12-31CVE-2005-4787: Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and…
PriorityP417medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.51%
71.3th percentile
Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it easier for us to troubleshoot when issues arise on individual carts. For someone to have a script to do this type of search would require that they know where your shop is actually located. I dont think it really can be construde [sic] as a security issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| turnkey_solutions | sunshop_shopping_cart | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/17832http://www.turnkeywebtools.com/forum/showpost.php?p=9874&postcount=6http://www.turnkeywebtools.com/forum/showthread.php?t=2384http://secunia.com/advisories/17832http://www.turnkeywebtools.com/forum/showpost.php?p=9874&postcount=6http://www.turnkeywebtools.com/forum/showthread.php?t=2384
2005-12-31
Published