EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Ezshopper |
Alex_heiphetz_group |
3.0 (including) |
3.0 (including) |
References