UltraCMS 0.9 suffers from an SQL injection vulnerability which can be used to gain administrative privileges.