CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.
Date published : 2013-11-14
http://www.securityfocus.com/bid/62937
http://archives.neohapsis.com/archives/bugtraq/2013-11/0026.html