SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/52486http://www.exploit-db.com/exploits/9440