code-projects School Fees Payment System 1.0 contains a sql injection caused by manipulation of the "ID" argument in /student.php, letting remote attackers execute arbitrary SQL commands, exploit ...