SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Zen_cart | Zen_cart | 1.1.3 (including) | 1.1.3 (including) |
References