Product
An unauthenticated SQL injection vulnerability in the delete.php file of Simple Inventory System 1.0 allows remote attackers to execute arbitrary database queries via the ID parameter.