SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41817http://www.vupen.com/english/advisories/2008/1242/referenceshttp://www.securityfocus.com/bid/28779http://www.securityfocus.com/archive/1/490889/100/0/threadedhttp://securityreason.com/securityalert/3843http://secunia.com/advisories/29789https://www.exploit-db.com/exploits/5448