SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter.Referenceshttp://www.securityfocus.com/archive/1/497970http://secunia.com/advisories/32272http://www.securityfocus.com/bid/31993https://exchange.xforce.ibmcloud.com/vulnerabilities/46205http://securityreason.com/securityalert/4550