shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Shopplus_cart | Kabotie_software_technologies | * | * |
References