CVE-2015-0919 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.12% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-01-08 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sefrengo | sefrengo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sefrengo CMS 1.6.0 - SQL Injection | 2015-01-07 |
References
- http://forum.sefrengo.org/index.php?showtopic=3360
- http://packetstormsecurity.com/files/129824/Sefrengo-CMS-1.6.0-SQL-Injection.html
- http://seclists.org/fulldisclosure/2015/Jan/9
- http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-04.html
- http://forum.sefrengo.org/index.php?showtopic=3360
- http://packetstormsecurity.com/files/129824/Sefrengo-CMS-1.6.0-SQL-Injection.html
- http://seclists.org/fulldisclosure/2015/Jan/9
- http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-04.html
→ the Explorer · watch your stack · NVD