Product
An unauthenticated SQL injection vulnerability in itsourcecode Sales and Inventory System 1.0 allows remote attackers to manipulate the User parameter in processlogin.php to execute arbitrary SQL commands.