SQL injection vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to execute arbitrary SQL commands via the LinkServID parameter.Referenceshttp://www.securityfocus.com/bid/29346http://secunia.com/advisories/30367http://osvdb.org/45616https://exchange.xforce.ibmcloud.com/vulnerabilities/49225http://holisticinfosec.org/content/view/67/45/