Description
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.
Affected products
- cgicentral / webstore_4004.14 – 4.14
- cgicentral / webstore_400cs4.14 – 4.14