SQL Injection in dingfanzuCMS v.1.0 Enables Arbitrary Code Execution
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a malicious user to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.