vendor:
Stockman Shopping Cart
by:
Spabam
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Stockman Shopping Cart
Affected Version From: 7.8
Affected Version To: 7.8
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
Stockman Shopping Cart Remote Command Execution Vulnerability
Stockman Shopping Cart has been reported prone to a remote command execution vulnerability. This issue presents itself in the 'shop.plx' script. The problem results from a lack of sufficient sanitization performed on user supplied URI parameters to the 'shop.plx' script. An attacker may exploit this vulnerability to execute arbitrary commands in the context of the web server hosting the vulnerable script.
Mitigation:
Sanitize user supplied URI parameters to the 'shop.plx' script.