CVE-2015-0919
Sefrengo < 1.6.0 - Authenticated SQL Injection via idcat or idclient Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-0919. PoCs published by Steffen Rösemann.
AI-analyzed exploit summary The advisory describes SQL injection vulnerabilities in Sefrengo CMS v1.6.0, specifically in the 'idcat' and 'idclient' parameters of the administrative backend. Exploit examples are provided to demonstrate the injection points.
Description
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.
Exploits (1)
The advisory describes SQL injection vulnerabilities in Sefrengo CMS v1.6.0, specifically in the 'idcat' and 'idclient' parameters of the administrative backend. Exploit examples are provided to demonstrate the injection points.