SQL injection vulnerability in lesson.php in Alqatari Q R Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.Referenceshttp://packetstormsecurity.org/0909-exploits/alqatarigroup-sql.txthttp://secunia.com/advisories/36554