SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote malicious user to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.