CVE-2015-0919

Publication date

2015-01-08 15:00:00

Family

mitre

State

PUBLISHED

Description

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.