See how online book store project project compares to other vendors in security performance
The 'bookisbn' parameter of the cart.php resource
does not validate the characters received and they
are sent unfiltered to the database.
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.