vendor:
CubeCart PHP Free & Commercial Shopping Cart Application
by:
7Safe
N/A
CVSS
N/A
SQL injection
89
CWE
Product Name: CubeCart PHP Free & Commercial Shopping Cart Application
Affected Version From: CubeCart v.4.3.4
Affected Version To: CubeCart v.4.3.9
Patch Exists: NO
Related CWE: CVE-2010-1931
CPE: a:cubecart:cubecart:4.3.4
Platforms Tested:
2010
SQL Injection in CubeCart PHP Free & Commercial Shopping Cart Application
There is an SQL Injection vulnerability in the CubeCart PHP Shopping cart, this vulnerability may be exploited by 'HTTP POST'ing malicious data to the index.php script of CubeCart. As an example, exploitation may result in leak of sensitive information or injection of malicious code into the shopping cart's web page.
Mitigation:
Upgrade to the latest version of CubeCart