CVE-2014-8306

C97net Cart Engine < 3.0 - SQL Injection via item_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8306.

AI-analyzed exploit summary The provided exploit code demonstrates multiple vulnerabilities in Cart Engine 3.0, including SQL injection via unsanitized 'item_id' parameters, reflected XSS through unneutralized output, and open redirect via untrusted HTTP Referer header. The PoC includes detailed HTTP requests for each vulnerability type.

Description

SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/34764

The provided exploit code demonstrates multiple vulnerabilities in Cart Engine 3.0, including SQL injection via unsanitized 'item_id' parameters, reflected XSS through unneutralized output, and open redirect via untrusted HTTP Referer header. The PoC includes detailed HTTP requests for each vulnerability type.

Classification
Working Poc 95%
Attack Type
Sqli | Xss | Other
Complexity
Moderate
Reliability
Reliable
Target: Cart Engine 3.0
No auth needed
Prerequisites: Access to the target web application · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2

Scores

EPSS 0.0124
EPSS Percentile 65.3%

Details

CWE
CWE-89
Status published
Products (1)
c97/cart_engine < 3.0
Published Oct 16, 2014
Tracked Since Feb 18, 2026