Sefrengo CMS management background SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
Sefrengo 1.6.0
Description:
CVE (CAN) ID: CVE-2015-0919
Sefrengo CMS is an open-source Web content management system.
Multiple SQL injection vulnerabilities exist in the management background of Sefrengo CMS versions earlier than 1.6.1. remote administrators can exploit this vulnerability to execute arbitrary SQL commands by passing idcat and idclient parameters to backend/main. php. This vulnerability is located at: http: // % 7 Btarget % 7D/backend/main. php? Area = con_configcat & idcat = 1 & idtplconf = 0
<* Source: Steffen R & #246; semann
Link: http://seclists.org/fulldisclosure/2015/Jan/9
*>
Suggestion:
Vendor patch:
Sefrengo
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://forum.sefrengo.org/index.php? Showtopic = 3360
Http://www.sefrengo.org/start/start.html
Http://sroesemann.blogspot.de
This article permanently updates the link address: