CVE-2009-3319
SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec list action, a different vector than CVE-2006-1018.
Date published : 2009-09-23
http://www.securityfocus.com/bid/16909
http://www.securityfocus.com/archive/1/506616/100/0/threaded