SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.
- http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html
No PoCs found on GitHub currently.