SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.Referenceshttp://www.securityfocus.com/bid/32339http://osvdb.org/49916http://secunia.com/advisories/32727https://exchange.xforce.ibmcloud.com/vulnerabilities/46675https://www.exploit-db.com/exploits/7146