In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.