Security Advisory

CVE-2014-3978

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-10-20 16:00:00
Last updated 2024-08-06 11:04:26
Assigner mitre
State PUBLISHED

Description

SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.