Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2000-0400
http://www.securityfocus.com/bid/1256
http://www.pdgsoft.com/Security/security2.html