WebAsyst Shop-Script SQL Injection and Cross Site Scripting Vulnerability
Description
A vulnerability has been identified in WebAsyst Shop-Script, which could be exploited by attackers to inject SQL queries or scripting code. This issue is caused by input validation errors in the "index.php" script when processing the "blog_id" parameter while "ukey" is set to "news", which could be exploited by malicious people to conduct SQL injection or cross site scripting attacks.