SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.Referenceshttps://www.exploit-db.com/exploits/7250https://exchange.xforce.ibmcloud.com/vulnerabilities/46920http://www.osvdb.org/50313http://packetstormsecurity.com/0811-exploits/rakhi-sqlxssfpd.txthttp://secunia.com/advisories/32897