SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/47701http://www.securityfocus.com/bid/33081http://secunia.com/advisories/33363http://osvdb.org/51110https://www.exploit-db.com/exploits/7641