wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.
Link | Tags |
---|---|
http://securitytracker.com/id?1014480 | vdb entry |
http://marc.info/?l=bugtraq&m=112128870110418&w=2 | mailing list |
http://secunia.com/advisories/15780 | third party advisory |
http://www.securityfocus.com/bid/14245 | vdb entry |