CVE-2015-0919

Sefrengo < 1.6.0 - Authenticated SQL Injection via idcat or idclient Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-0919. PoCs published by Steffen Rösemann.

AI-analyzed exploit summary The advisory describes SQL injection vulnerabilities in Sefrengo CMS v1.6.0, specifically in the 'idcat' and 'idclient' parameters of the administrative backend. Exploit examples are provided to demonstrate the injection points.

Description

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.

Exploits (1)

exploitdb WRITEUP
by Steffen Rösemann · textwebappsphp
https://www.exploit-db.com/exploits/35722

The advisory describes SQL injection vulnerabilities in Sefrengo CMS v1.6.0, specifically in the 'idcat' and 'idclient' parameters of the administrative backend. Exploit examples are provided to demonstrate the injection points.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Sefrengo CMS v1.6.0
Auth required
Prerequisites: Access to the administrative backend · Ability to craft malicious URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

EPSS 0.0212
EPSS Percentile 79.5%

Details

CWE
CWE-89
Status published
Products (1)
sefrengo/sefrengo < 1.6.0
Published Jan 08, 2015
Tracked Since Feb 18, 2026