SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.Referenceshttp://www.securityfocus.com/bid/29642https://www.exploit-db.com/exploits/5776http://securityreason.com/securityalert/4654https://exchange.xforce.ibmcloud.com/vulnerabilities/42954