CVE
- Id
- 3427
- CVE No.
- CVE-2001-0614
- Status
- Candidate
- Description
- Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.
- Phase
- Proposed (20010727)
- Votes
- ACCEPT(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop
- Comments
- Christey> Give the particular nature of the constructed URL, i.e. the | command is specified in the VBEXE parameter.