[原文]Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.
PHPFreeNews contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the SearchResults.php script not properly sanitizing user-supplied input to the 'Match' and 'CatID' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
Upgrade to version 1.41 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.