First published: Tue Apr 26 2005(Updated: )
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-cart | =2004_1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1289 is considered to be a critical vulnerability due to the potential for remote command execution.
To fix CVE-2005-1289, upgrade to a version of E-Cart later than 2004 1.1 that does not contain this vulnerability.
Exploiting CVE-2005-1289 allows attackers to execute arbitrary commands on the server, compromising the system's security.
CVE-2005-1289 affects E-Cart 2004 version 1.1 and earlier.
Mitigation without upgrading is challenging, but input validation and sanitization could reduce the risk of exploitation.