7.5
CVSSv2

CVE-2001-1343

Published: 12/06/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cgicentral webstore 400cs 4.14

cgicentral webstore 400 4.14

Exploits

source: wwwsecurityfocuscom/bid/2861/info cgiCentral's Webstore is an shopping cart application which processes and manages online purchases Ws_mailcgi calls system() with user-supplied data in the command string Because it does not filter metacharacters out of the user-supplied data, it is possible for administrators to execute arbi ...