It is possible for a remote user to execute arbitrary commands on a host using Carello Shopping Cart software. A specially crafted HTTP request could cause inetinfo.exe to consume all available system resources, refusing any new connections. If arbitrary code is part of the HTTP request, it will be executed with the privileges of the web server.
Carello contains a flaw that may allow a malicious user to execute arbitrary code or cause a denial of service. The issue is triggered when a specially crafted HTTP request is sent to the Carello.dll library. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
Upgrade to version 1.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.