index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
References
Configurations
History
20 Nov 2024, 23:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111428818425864&w=2 - | |
References | () http://secunia.com/advisories/15054 - | |
References | () http://securitytracker.com/id?1013780 - Exploit |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:57
NVD link : CVE-2005-1289
Mitre link : CVE-2005-1289
CVE.ORG link : CVE-2005-1289
JSON object : View
Products Affected
e-cart
- e-cart
CWE