CVE-2007-0133
iGeneric iG Shop < 1.4 - SQL Injection via id or user_login_cookie Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0133.
AI-analyzed exploit summary The exploit demonstrates arbitrary code execution via eval injection in 'cart.php' and 'page.php', as well as SQL injection in 'compare_product.php'. It includes functional payloads to dump credit card numbers and user logins.
Description
Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.
Exploits (1)
The exploit demonstrates arbitrary code execution via eval injection in 'cart.php' and 'page.php', as well as SQL injection in 'compare_product.php'. It includes functional payloads to dump credit card numbers and user logins.