EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Ezshopper | Alex_heiphetz_group | 3.0 (including) | 3.0 (including) |
References