SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.
https://www.exploit-db.com/exploits/6574
https://www.exploit-db.com/exploits/6572
https://exchange.xforce.ibmcloud.com/vulnerabilities/45433