SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/61600
http://www.vupen.com/english/advisories/2010/2297