Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Auction_weaver | Cgi_script_center | 1.0 (including) | 1.0 (including) |
Auction_weaver | Cgi_script_center | 1.02 (including) | 1.02 (including) |