Loading product vulnerabilities…
Total
2
Critical
0
High
0
Medium
0
CISA KEV
0
SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.
iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.