Microsoft Commerce Server 2000 OWC...

- AV AC AU C I A
发布: 2002-06-26
修订: 2025-04-13

Microsoft Commerce Server is a web server product for building, deploying, and analyzing e-commerce sites. A remote command execution vulnerability has been reported in some versions of Commerce Server 2000. The Office Web Component (OWC) package installer will accept an optional command as input. In the event that the attacker has a valid account on the server, including log on credentials, it is possible to cause an arbitrary command to be executed. The supplied command will execute with the privileges of the attacker's account.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息