WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
- https://www.exploit-db.com/exploits/44997/
No PoCs found on GitHub currently.