SQL injection vulnerability in rss.php in Article Script 1.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/30038
http://www.vupen.com/english/advisories/2006/4352