Loading...
Loading...
Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.
August 19, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-6985
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.