Description
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-0408)
Oracle Database Server CVE-2006-0291 Vulnerability (CVE-2006-0291)
WordPress Plugin Order Export & Order Import for WooCommerce Cross-Site Request Forgery (1.6.0)
WordPress Plugin Welcart e-Commerce Multiple SQL Injection Vulnerabilities (1.5.2)