PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Squirrelcart | Lighthouse_development | 1.5.5 (including) | 1.5.5 (including) |
| Squirrelcart | Lighthouse_development | 1.6 (including) | 1.6 (including) |
| Squirrelcart | Lighthouse_development | 2.2.2 (including) | 2.2.2 (including) |