XOOPS Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-4433
SQL injection vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops might allow remote attackers to execute arbitrary SQL commands via the itemsxpag parameter.