SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1471
Reference (s):
- https://github.com/delta/pragyan/commit/c93bc100ec93fc78940fbdca9b6b009101858309
- FULLDISC:20150203 SQL injection vulnerability in Pragyan CMS v.3.0
- URL: http://seclists.org/fulldisclosure/2015/Feb/18
- http://pastebin.com/ip2gGYuS
- http://sroesemann.blogspot.de/2015/01/sroeadv-2015-11.html