SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Index_script | Index_script | 2.8 (including) | 2.8 (including) |