Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/52940
http://www.vupen.com/english/advisories/2009/2494