index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| E-cart | E-cart | 2004_1.1 (including) | 2004_1.1 (including) |