SQL injection vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops might allow remote attackers to execute arbitrary SQL commands via the itemsxpag parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/45714
http://lostmon.blogspot.com/2008/08/rmsoft-minishop-module-multiple.html