CVE-2014-5140
03.01.2020, 20:15
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
Vendor | Product | Version |
---|---|---|
loadedcommerce | loaded7 | - |
𝑥
= Vulnerable software versions
References