SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Midicart_php_shopping_cart | Midicart_software | * | * |
References