CVE-2014-8306 | C97 Cart Engine prior 3.0 cart.php sql_query item_id[] sql injection (EDB-34764)
A vulnerability was found in C97 Cart Engine. It has been classified as critical. This affects the function sql_query of the file cart.php. The manipulation of the argument item_id[] leads to sql injection.
This vulnerability is uniquely identified as CVE-2014-8306. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.