Synopsis
The remote host is vulnerable to authentication bypass.
Description
The remote host is running the StockMan shopping cart.
According to the version number of the CGI shop.plx, there is a flaw in this installation that could allow an attacker to execute arbitrary commands on this host, and which could also allow him to obtain your list of customers or their credit card number.
Solution
Upgrade to StockMan Shopping Cart Version 7.9 or newer
Plugin Details
File Name: stockman_shopping_cart_cmd_exec.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7485