Description: A vulnerability has been reported in Zen Cart, which potentially can be exploited by malicious people to conduct SQL injection attacks.
Unspecified input is not properly sanitised in various files before being used in a SQL query. This can potentially be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Also, access to files in "admin/includes/" may not be properly restricted.
Solution: Update to version 1.2.7.
Provided and/or discovered by: Reported by vendor.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.