6.5
CVSSv2

CVE-2014-3978

Published: 20/10/2014 Updated: 24/10/2014
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tomatocart tomatocart 1.1.8.6.1

Exploits

Title: TomatoCart v1x (latest-stable) Remote SQL Injection Vulnerability Background: TomatoCart is open source ecommerce solution developed and maintained by a number of 64,000+ users from 50+ countries and regions It's distributed under the terms of the GNU General Public License (or "GPL"), free to download and share The community, in ...
TomatoCart version 1x (latest-stable) suffers from cross site scripting and remote SQL injection vulnerabilities ...