SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26720
http://www.securityfocus.com/archive/1/435166/30/4680/threaded