SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the template parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
E-vision_cms | E-vision | * | 2.02 (including) |