The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Dansie_shopping_cart |
Craig_dansie |
3.0.4 (including) |
3.0.4 (including) |
References