PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
CVE Status: Modified
No CVSS data available
Exploit-db Github