SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.Referenceshttp://www.securityfocus.com/bid/30772http://www.packetstormsecurity.org/0808-exploits/dxshopcart-sql.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/44582