Description
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin ElasticPress Cross-Site Request Forgery (3.5.3)
WordPress Plugin 3D Slider Slice Box Multiple Cross-Site Scripting Vulnerabilities (1.0)
PHP Improper Input Validation Vulnerability (CVE-2013-4248)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2022-2097)