Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activateaddress address controller action, (2) title parameter in a show blog controller action, or (3) contentid parameter in a showComments expComment controller action.