SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39027http://www.securityfocus.com/archive/1/485035/100/0/threadedhttp://securityreason.com/securityalert/3465http://www.securityfocus.com/bid/26860