SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Cs-cart |
Cs-cart |
1.3.0 (including) |
1.3.0 (including) |
References