SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.Referenceshttp://securityreason.com/securityalert/2120http://www.securityfocus.com/archive/1/456127/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/31313http://secunia.com/advisories/23642http://www.securityfocus.com/bid/21905http://osvdb.org/31665http://www.vupen.com/english/advisories/2007/0080