CVE-2015-5078 - Unpainted Asskiss
Description
SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.
Reference
https://bugs.limesurvey.org/view.php?id=9720 https://github.com/LimeSurvey/LimeSurvey/commit/65d717415a271242b9a30a5330d4eabac1c1a837 https://bugs.limesurvey.org/plugin.php?page=Source/view&id=15509 http://www.securityfocus.com/bid/75440