{"api_version":"1","generated_at":"2026-07-23T04:56:52+00:00","cve":"CVE-2007-0134","urls":{"html":"https://cve.report/CVE-2007-0134","api":"https://cve.report/api/cve/CVE-2007-0134.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0134","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0134"},"summary":{"title":"CVE-2007-0134","description":"Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-09 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt","name":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/23604","name":"http://secunia.com/advisories/23604","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"iG Shop PHP \"eval()\" Injection and SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31301","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31301","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/471722/100/0/threaded","name":"http://www.securityfocus.com/archive/1/471722/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/456043/100/0/threaded","name":"http://www.securityfocus.com/archive/1/456043/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/33388","name":"http://osvdb.org/33388","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/0056","name":"http://www.vupen.com/english/advisories/2007/0056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.attrition.org/pipermail/vim/2007-June/001664.html","name":"http://www.attrition.org/pipermail/vim/2007-June/001664.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[VIM] Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21875","name":"http://www.securityfocus.com/bid/21875","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/33387","name":"http://osvdb.org/33387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/3083","name":"https://www.exploit-db.com/exploits/3083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"iG Shop 1.0 (eval/sql injection) Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0134","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0134","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"134","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"igeneric","cpe5":"ig_shop","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"134","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"igeneric","cpe5":"ig_shop","cpe6":"1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:37.182Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21875","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21875"},{"name":"3083","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/3083"},{"name":"33388","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33388"},{"name":"33387","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33387"},{"name":"20070619 iG Shop 1.4 eval Inclusion Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471722/100/0/threaded"},{"name":"23604","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23604"},{"name":"20070105 IG Shop remote code execution","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/456043/100/0/threaded"},{"name":"ADV-2007-0056","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0056"},{"name":"igshop-cartpage-code-execution(31301)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31301"},{"name":"20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit","tags":["mailing-list","x_refsource_VIM","x_transferred"],"url":"http://www.attrition.org/pipermail/vim/2007-June/001664.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21875","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21875"},{"name":"3083","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/3083"},{"name":"33388","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33388"},{"name":"33387","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33387"},{"name":"20070619 iG Shop 1.4 eval Inclusion Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/471722/100/0/threaded"},{"name":"23604","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23604"},{"name":"20070105 IG Shop remote code execution","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/456043/100/0/threaded"},{"name":"ADV-2007-0056","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0056"},{"name":"igshop-cartpage-code-execution(31301)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31301"},{"name":"20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit","tags":["mailing-list","x_refsource_VIM"],"url":"http://www.attrition.org/pipermail/vim/2007-June/001664.html"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0134","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21875","refsource":"BID","url":"http://www.securityfocus.com/bid/21875"},{"name":"3083","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/3083"},{"name":"33388","refsource":"OSVDB","url":"http://osvdb.org/33388"},{"name":"33387","refsource":"OSVDB","url":"http://osvdb.org/33387"},{"name":"20070619 iG Shop 1.4 eval Inclusion Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/471722/100/0/threaded"},{"name":"23604","refsource":"SECUNIA","url":"http://secunia.com/advisories/23604"},{"name":"20070105 IG Shop remote code execution","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/456043/100/0/threaded"},{"name":"ADV-2007-0056","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0056"},{"name":"igshop-cartpage-code-execution(31301)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31301"},{"name":"20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit","refsource":"VIM","url":"http://www.attrition.org/pipermail/vim/2007-June/001664.html"},{"name":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt","refsource":"MISC","url":"http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0134","datePublished":"2007-01-09T11:00:00.000Z","dateReserved":"2007-01-08T00:00:00.000Z","dateUpdated":"2024-08-07T12:03:37.182Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-09 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:igeneric:ig_shop:1.0:*:*:*:*:*:*:*","matchCriteriaId":"489C3CB5-312C-4BC6-87A7-E272FD6FC81B"},{"vulnerable":true,"criteria":"cpe:2.3:a:igeneric:ig_shop:1.4:*:*:*:*:*:*:*","matchCriteriaId":"390A6407-BFA4-444F-9D2D-58A2EC0FB0D1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"134","Ordinal":"1","Title":"CVE-2007-0134","CVE":"CVE-2007-0134","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"134","Ordinal":"1","NoteData":"Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.","Type":"Description","Title":"CVE-2007-0134"},{"CveYear":"2007","CveId":"134","Ordinal":"2","NoteData":"2007-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"134","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}