Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hassan Consulting Shopping Cart远程任意命令执行漏洞
Vulnerability Description
Hassan Consulting's Shopping Cart是一款商业性质电子商务软件。 Shopping Cart没有充分过滤来自WEB请求的用户输入,远程攻击者可以利用这个漏洞以WEB权限在系统上执行任意命令。 Shopping Cart中的shop.pl对用户提交给page参数的输入缺少检查,提交类似";command|"的字符串,就可能以WEB进程权限在系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A