Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3w8-wjw3-m7v2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.

Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.

EPSS

Процентиль: 94%
0.14145
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
около 19 лет назад

Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php. NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.

EPSS

Процентиль: 94%
0.14145
Средний

Дефекты

CWE-94