CVE-2005-1289
e-cart 2004 1.1 - Remote Command Execution via Shell Metacharacters in art Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1289. PoCs published by z.
AI-analyzed exploit summary This Perl script exploits a command injection vulnerability in E-Cart E-Commerce Software (CVE-2005-1289) by injecting a reverse shell payload via the 'art' parameter in the index.cgi script. It generates a Perl-based reverse shell script on the target system and triggers it to connect back to the attacker's specified IP and port.
Description
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
Exploits (1)
This Perl script exploits a command injection vulnerability in E-Cart E-Commerce Software (CVE-2005-1289) by injecting a reverse shell payload via the 'art' parameter in the index.cgi script. It generates a Perl-based reverse shell script on the target system and triggers it to connect back to the attacker's specified IP and port.