SQL injection vulnerability in show.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.Referenceshttp://osvdb.org/65994http://www.vupen.com/english/advisories/2010/1690http://secunia.com/advisories/40450https://exchange.xforce.ibmcloud.com/vulnerabilities/60075http://www.securityfocus.com/bid/41341http://www.exploit-db.com/exploits/14199