School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
https://www.exploit-db.com/exploits/45722/
http://packetstormsecurity.com/files/150014/School-Event-Management-System-1.0-SQL-Injection.html