SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.Referenceshttp://www.exploit-db.com/exploits/9351http://secunia.com/advisories/36100