peter bassill · operator
$ cve CVE-2007-0134 JSON

CVE-2007-0134 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 11.4% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS11.41% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2007-01-09
Last modified2026-06-16

Affected (1)

VendorProduct
igenericig shop

Public exploits

SourceTitleDate
exploit-dbig shop 1.0 - Code Execution / SQL Injection2007-01-05

References

→ the Explorer  ·  watch your stack  ·  NVD