js/pages/pagesdata.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magicquotesgpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTPXFORWARDEDFOR environment variable) in an HTTP header.