CVE-2014-8306
C97net Cart Engine < 3.0 - SQL Injection via item_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8306.
AI-analyzed exploit summary The provided exploit code demonstrates multiple vulnerabilities in Cart Engine 3.0, including SQL injection via unsanitized 'item_id' parameters, reflected XSS through unneutralized output, and open redirect via untrusted HTTP Referer header. The PoC includes detailed HTTP requests for each vulnerability type.
Description
SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.
Exploits (1)
The provided exploit code demonstrates multiple vulnerabilities in Cart Engine 3.0, including SQL injection via unsanitized 'item_id' parameters, reflected XSS through unneutralized output, and open redirect via untrusted HTTP Referer header. The PoC includes detailed HTTP requests for each vulnerability type.