SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.Referenceshttp://www.securityfocus.com/bid/32556https://www.exploit-db.com/exploits/7311https://exchange.xforce.ibmcloud.com/vulnerabilities/46938