CVE-2015-0919 Information

Description

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.

Reference

http://forum.sefrengo.org/index.php?showtopic=3360 http://packetstormsecurity.com/files/129824/Sefrengo-CMS-1.6.0-SQL-Injection.html http://seclists.org/fulldisclosure/2015/Jan/9 http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-04.html

Share on: