Acg · Acgv News · CVE-2007-4603
**Name of the Vulnerable Software and Affected Versions**
ACG News version 1.0
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `aid` parameter in a "showarticle" action or the `catid` parameter in a "showcat" action in the index.php file.
**Recommendations**
For ACG News version 1.0, consider restricting access to the index.php file until a patch is available, and avoid using the `aid` and `catid` parameters in the affected actions.