SQL injection vulnerability in index.php in iSupport 1.06 allows remote attackers to execute arbitrary SQL commands via the include_file parameter.Referenceshttp://www.osvdb.org/21317http://pridels0.blogspot.com/2005/11/isupport-1x-includefile-sql-inj.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/24356