TuziCMS 2.0.6 has SQL injection via index.php