CVE-2014-8306
C97 Cart Engine < 3.0 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.
Exploits (1)
Scores
EPSS
0.0174
EPSS Percentile
82.5%
Details
CWE
CWE-89
Status
published
Products (1)
c97/cart_engine
< 3.0
Published
Oct 16, 2014
Tracked Since
Feb 18, 2026