Webscriptworld Web Shop Manager Remote Arbitrary Command Execution Vulnerability

Web Shop Manager is a freely available, open source web store script. It is available for Unix, Linux, and Microsoft Windows operating systems.

Web Shop Manager does not sufficiently filter user-supplied input. Because of this, it is possible for a remote user to pass arbitrary commands through the script which will be executed in a shell on the local host. These commands would be executed with the privileges of the web server process.


Privacy Statement
Copyright 2010, SecurityFocus