The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dansie_shopping_cart | Craig_dansie | 3.0.4 (including) | 3.0.4 (including) |