Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2007-01-09T11:00:00
Updated: 2024-08-07T12:03:37.182Z
Reserved: 2007-01-08T00:00:00
Link: CVE-2007-0134

No data.

Status : Deferred
Published: 2007-01-09T11:28:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-0134

No data.