SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/47791https://www.exploit-db.com/exploits/7686http://www.securityfocus.com/bid/33139