SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.
https://www.exploit-db.com/exploits/6159
https://exchange.xforce.ibmcloud.com/vulnerabilities/44054
http://www.securityfocus.com/bid/30423
http://www.securityfocus.com/archive/1/494866/100/0/threaded
http://svn.gregarius.net/trac/changeset/1788/trunk/gregarius/ajax.php