SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ihtml_merchant | Ihtml_merchant | 2_pro (including) | 2_pro (including) |