SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1450
Reference (s):
- http://packetstormsecurity.com/files/130122/Restaurantbiller-SQL-Injection-Shell-Upload.html