Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.
http://www.securityfocus.com/bid/42408
http://www.pligg.com/blog/991/pligg-cms-1-1-1-release/