SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Primo_cart | Primo_place | * | 1.0 (including) |