Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TomatoCart SQL注入漏洞
Vulnerability Description
TomatoCart是一套使用PHP开发的开源电子商务软件。该软件包含产品分类、产品评论、文章发布等模块。 TomatoCart 1.1.8.6.1版本中存在SQL注入漏洞。远程攻击者可借助新地址联系薄中的‘First Name’和‘Last Name’字段利用该漏洞执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A