SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter.Referenceshttp://www.vulnerability-lab.com/get_content.php?id=512http://www.exploit-db.com/exploits/18872