VUPEN Web Vulnerability Research Team discovered 27 vulnerabilities in WebAsyst Shop-Script FREE. These issues are caused by input validation errors in various scripts when processing user-supplied data and parameters, which could allow local file inclusion, sql injection and cross site scripting attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88444/webasyst-lfisql.txt
Source: https://packetstormsecurity.com/files/88444/WebAsyst-Shop-Script-Input-Validation.html

