Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.Referenceshttp://osvdb.org/50326http://secunia.com/advisories/32950http://www.securityfocus.com/bid/32563http://packetstormsecurity.com/0811-exploits/rakhi-sqlxssfpd.txt