It looks like Bugtraq IDs 42539 and 43257 are covering the same vulnerability -- a SQL injection involving the cid parameter of shop.htm in PPScript. Rob? George -- theall at tenablesecurity.com