Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.