SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.
- http://securityreason.com/securityalert/3544
- https://www.exploit-db.com/exploits/4882
No PoCs found on GitHub currently.