index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
E-cart | E-cart | 2004_1.1 (including) | 2004_1.1 (including) |