See how online book store project project compares to other vendors in security performance
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
The 'bookisbn' parameter of the cart.php resource
does not validate the characters received and they
are sent unfiltered to the database.