ndCMS - SQL Injection
This advisory describes a SQL injection vulnerability in ndCMS v0.4rc1, specifically in the 'express_edit/editor.aspx' file. The vulnerability allows an attacker to inject malicious SQL queries via the 'indx' parameter.