← Back

CVE-2015-0919

nvd nist
Published: Jan 8, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.

Affected (1)

Products: Sefrengo: Sefrengo
1 product
Sefrengo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.6.0

References (8)

Timeline

No history available yet.