An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
https://www.exploit-db.com/exploits/48916
https://packetstormsecurity.com/files/159132/Mobile-Shop-System-1.0-SQL-Injection.html