SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
| Software | From | Fixed in |
|---|---|---|
| etomite / etomite | - | 0.6.1.x |
| etomite / etomite | 0.6 | 0.6.x |