CVE-2014-3978 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.
Reference
http://packetstormsecurity.com/files/127785/TomatoCart-1.x-Cross-Site-Scripting-SQL-Injection.html https://breaking.technology/advisories/CVE-2014-3978.txt
Share on: