The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T11:34:37.518Z

Reserved: 2014-07-30T00:00:00

Link: CVE-2014-5140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-03T20:15:11.730

Modified: 2024-11-21T02:11:29.817

Link: CVE-2014-5140

cve-icon Redhat

No data.