SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/90459http://www.exploit-db.com/exploits/30689http://osvdb.org/show/osvdb/102207