Vulnerabilities > CVE-2001-0614 - Unspecified vulnerability in Carello E-Commerce
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Pacific Software Carello 1.2.1 Shopping Cart Command Execution Vulnerability. CVE-2001-0614 . Remote exploit for windows platform |
id | EDB-ID:20850 |
last seen | 2016-02-02 |
modified | 2001-05-14 |
published | 2001-05-14 |
reporter | Peter Gründl |
source | https://www.exploit-db.com/download/20850/ |
title | Pacific Software Carello 1.2.1 Shopping Cart Command Execution Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | CARELLO.NASL |
description | The remote host appears to be running Carello.dll, a web-based shopping cart. Versions up to 1.3 of this web shopping cart have a command execution vulnerability. This could allow a remote attacker to run arbitrary commands on the system with the privileges of the web server. *** Note that no attack was performed, and the version number was *** not checked, so this might be a false alert |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11776 |
published | 2003-06-26 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11776 |
title | Carello E-Commerce Carello.dll Command Execution |
code |
|