OneOrZero AIMS v2.6.0 Members Edition Multiple Vulnerabilities

Please view the original advisory/exploit here.

The web app OneOrZero AIMS Members Edition suffers from multiple remote vulnerabilities.

SQL Injection
Multiple scripts and parameters are affected by remote SQL injection vulnerabilities.
You can also manipulate SQL queries with the help of various search fields of this
web app.

Some example URLs:
index.php?controller=app_oneorzerohelpdesk_main&subcontroller=search_management_manage&option=saved_search&global=1&id=[SQL Injection]
index.php?controller=app_oneorzerohelpdesk_main&subcontroller=search_management_manage&option=show_item_search&item_types=[SQL Injection]

Local File Inclusion
This vulnerability can be tricky to exploit. If OpenBaseDir is set, you can at least
view files in the directory of this web software.