Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2015-0919

Description

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.

POC

Reference

- http://packetstormsecurity.com/files/129824/Sefrengo-CMS-1.6.0-SQL-Injection.html

- http://seclists.org/fulldisclosure/2015/Jan/9

Github

No PoCs found on GitHub currently.