Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Paypal_storefront | Esmi | 1.7 (including) | 1.7 (including) |