SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kshop | Kaotik | * | 1.17 (including) |