SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/21672
https://exchange.xforce.ibmcloud.com/vulnerabilities/20956
http://www.securityfocus.com/bid/13881
http://securitytracker.com/id?1014129