SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- http://packetstormsecurity.org/0907-exploits/universecms-sql.txt
No PoCs found on GitHub currently.