CVE-2013-3536
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.
Date published : 2013-05-13
http://www.exploit-db.com/exploits/24934
http://packetstormsecurity.com/files/121046/WHMCS-Grouppay-1.5-SQL-Injection.html
