vendor:
E-Commerce Software
by:
z\
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: E-Commerce Software
Affected Version From: E-Cart 2004 v1.1 and below
Affected Version To: E-Cart 2004 v1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
Remote Command Execution Vulnerability in E-Cart E-Commerce Software
The vulnerability allows remote attackers to execute arbitrary commands via the index.cgi script, related to improper shell metacharacter handling in the art parameter.
Mitigation:
Upgrade to a version higher than E-Cart 2004 v1.1 or apply patches if available.