phpShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to shop/flypage not properly sanitizing user-supplied input to the 'product_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
SQLi p0c:
http://localhost/phpshop 2.0/?page=admin/function_list&module_id=11'
union select 1,database(),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 --