whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
whatsns 4.0 allows index.php?admincategory/remove.html cid[] SQL injection.
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?adminbanned/add.htm.