IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
BID:21875
Info
IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
| Bugtraq ID: | 21875 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0134 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2007 12:00AM |
| Updated: | Jun 19 2007 10:19PM |
| Credit: | Michael Brooks is credited with the discovery of this vulnerability. |
| Vulnerable: |
iGeneric iG Shop 1.4 iGeneric iG Shop 1.0 |
| Not Vulnerable: | |
Discussion
IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
The iG Shop application is prone to multiple PHP code-execution vulnerabilities.
An attacker can exploit these issues to execute arbitrary malicious PHP code in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
These issues affect iG Shop 1.0 and 1.4; other versions may be vulnerable as well.
The iG Shop application is prone to multiple PHP code-execution vulnerabilities.
An attacker can exploit these issues to execute arbitrary malicious PHP code in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
These issues affect iG Shop 1.0 and 1.4; other versions may be vulnerable as well.
Exploit / POC
IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example exploit is available:
Attackers can use a browser to exploit these issues.
The following example exploit is available:
Solution / Fix
IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
IGeneric IG Shop Multiple PHP Code Execution Vulnerabilities
References:
References: