Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.
arastta ecommerce 1.6.2