SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.Referenceshttp://osvdb.org/70655https://exchange.xforce.ibmcloud.com/vulnerabilities/64828http://www.securityfocus.com/bid/45913http://securityreason.com/wlb_show/WLB-2011010077