phpShop versions 0.7.1 and below have a flaw where it is possible for an attacker to execute arbitrary code as the server.