CVE
- Id
- 3790
- CVE No.
- CVE-2001-0985
- Status
- Candidate
- Description
- shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall
- Comments
- Green> THIS VULNERABILITY IS SUFFICIENTLY DISTINCT FROM A DIRECTORY | TRANSVERSAL TO WARRANT INCLUSION