Description
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin ImageMagick Engine Cross-Site Request Forgery (1.7.4)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2865)
WordPress Plugin WP-UserOnline URL HTML Injection (2.62)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)