Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Auction_weaver | Cgi_script_center | 1.0 (including) | 1.0 (including) |
| Auction_weaver | Cgi_script_center | 1.02 (including) | 1.02 (including) |