SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.Referenceshttp://www.exploit-db.com/exploits/13949https://exchange.xforce.ibmcloud.com/vulnerabilities/59581http://www.securityfocus.com/bid/40993