vendor:
SoftCart
by:
skape, trew
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: SoftCart
Affected Version From: 4.00b
Affected Version To: 4.00b
Patch Exists: NO
Related CWE: CVE-2004-2221
CPE: a:mercantec:softcart
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: BSDi
2004
Mercantec SoftCart CGI Overflow
This is an exploit for an undisclosed buffer overflow in the SoftCart.exe CGI as shipped with Mercantec's shopping cart software. It is possible to execute arbitrary code by passing a malformed CGI parameter in an HTTP GET request. This issue is known to affect SoftCart version 4.00b.
Mitigation:
No known mitigation or remediation for this vulnerability