Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.Referenceshttp://www.exploit-db.com/exploits/11602https://exchange.xforce.ibmcloud.com/vulnerabilities/56587http://packetstormsecurity.org/1002-exploits/hazelpresslite-sql.txt