CVE-2009-4748 | Andrew Charlton My Category Order up to 2.6.1a mycategoryorder.php parentID sql injection (EDB-9150 / XFDB-51727)
A vulnerability was found in Andrew Charlton My Category Order up to 2.6.1a and classified as critical. Affected is an unknown function of the file mycategoryorder.php. The manipulation of the argument parentID results in sql injection.
This vulnerability is reported as CVE-2009-4748. The attack can be launched remotely. Moreover, an exploit is present.