Php · Betster · CVE-2015-2237
**Name of the Vulnerable Software and Affected Versions**
Betster (aka PHP Betoffice) version 1.0.4
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `id` parameter to "showprofile.php" or "categoryedit.php", or the `username` parameter in a login to "index.php".
**Recommendations**
For Betster (aka PHP Betoffice) version 1.0.4, consider restricting access to the "showprofile.php", "categoryedit.php", and "index.php" scripts until a patch is available. As a temporary workaround, avoid using the `id` and `username` parameters in the affected API endpoints.