SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
- https://www.exploit-db.com/exploits/42982/
No PoCs found on GitHub currently.