CVE-2007-0134
HIGH 7.5EPSS 11.4%
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 11.41% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2007-01-09
- Updated
- 2024-08-07