SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cs-cart | Cs-cart | 1.3.0 (including) | 1.3.0 (including) |