Arbitrary Command Execution in Hassan Consulting Shopping Cart 1.23 via page Parameter

Arbitrary Command Execution in Hassan Consulting Shopping Cart 1.23 via page Parameter

CVE-2001-0985 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.

Learn more about our Web Application Penetration Testing UK.