CVE-2007-0132
iGeneric iG Shop 1.4 - SQL Injection via compare_product.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0132. PoCs published by Michael Brooks.
AI-analyzed exploit summary This exploit demonstrates an eval injection vulnerability in ig-shop, allowing arbitrary PHP code execution via the 'action' parameter in cart.php and page.php. It also includes SQL injection examples to dump credit card numbers and user logins.
Description
SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates an eval injection vulnerability in ig-shop, allowing arbitrary PHP code execution via the 'action' parameter in cart.php and page.php. It also includes SQL injection examples to dump credit card numbers and user logins.