Igeneric's vulnerability footprint centers on a small portfolio of e-commerce and calendar web applications, including its shopping cart and scheduling products, that serve small-to-medium business deployments. The vendor's durable signal is a recurring exposure to code-injection vulnerabilities, a class endemic to dynamic web application architecture and reflected across its product line; while public exploit code availability has been elevated for this vendor's disclosures, live exploitation and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Igeneric over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0134HIGH Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function cal | Jan 9, 2007 | 7.5 | 36 | NO | YES |
CVE-2007-2717HIGH SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector tha | May 16, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0130HIGH SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0132HIGH SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0133HIGH Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user | Jan 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-0537HIGH Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u | Feb 21, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Igeneric.
Media articles that mention a CVE ID that affects a product developed by Igeneric — matched by CVE ID, not by vendor name.