Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.Referenceshttp://www.andreafabrizi.it/?exploits:phpshophttp://secunia.com/advisories/31948http://www.securityfocus.com/bid/37227https://exchange.xforce.ibmcloud.com/vulnerabilities/54589http://www.securityfocus.com/archive/1/508270/100/0/threaded