Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fineshop | Looknet | * | 3.0 (including) |