SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Primo_cart |
Primo_place |
* |
1.0 (including) |
References