SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
| Software | From | Fixed in |
|---|---|---|
| cosmoshop / cosmoshop | - | 8.11.106.x |
| cosmoshop / cosmoshop | 8.10.78 | 8.10.78.x |