Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1931. PoCs published by Core Security.
AI-analyzed exploit summary The advisory describes an SQL injection vulnerability in CubeCart versions 4.3.4 to 4.3.9, where the 'shipKey' parameter in a POST request to 'index.php' is not properly sanitized, allowing arbitrary SQL code execution. The vulnerability is patched in version 4.4.0.
Description
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.
Exploits (1)
The advisory describes an SQL injection vulnerability in CubeCart versions 4.3.4 to 4.3.9, where the 'shipKey' parameter in a POST request to 'index.php' is not properly sanitized, allowing arbitrary SQL code execution. The vulnerability is patched in version 4.4.0.