RULE(RULE ID:335567)

Rule General Information
Release Date: 2021-12-20
Rule Name: WordPress Cart66 Lite Plugin SQL Injection Vulnerability (CVE-2014-9305)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:35459
http://packetstormsecurity.com/files/129395/Cart66-Lite-WordPress-Ecommerce-1.5.1.17-SQL-Injection.html
http://security.szurek.pl/cart66-lite-wordpress-ecommerce-15117-blind-sql-injection.html
https://wordpress.org/plugins/cart66-lite/changelog/
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://wordpress.org/plugins/cart66-lite/changelog/