Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22047
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2789