SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Kshop |
Kaotik |
* |
1.17 (including) |
References