Vulnerabilities > CVE-2005-1289 - Unspecified vulnerability in E-Cart 20041.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
e-cart
exploit available

Summary

index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.

Vulnerable Configurations

Part Description Count
Application
E-Cart
1

Exploit-Db

descriptionE-Cart <= 1.1 (index.cgi) Remote Command Execution Exploit. CVE-2005-1289. Webapps exploit for cgi platform
idEDB-ID:954
last seen2016-01-31
modified2005-04-25
published2005-04-25
reporterz
sourcehttps://www.exploit-db.com/download/954/
titleE-Cart <= 1.1 index.cgi Remote Command Execution Exploit