SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.Referenceshttp://www.securityfocus.com/archive/1/514376/100/0/threadedhttp://www.htbridge.ch/advisory/sql_injection_in_4site_cms.htmlhttp://secunia.com/advisories/33733http://www.securityfocus.com/bid/44258