Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENTIP, (3) XFORWARDEDFOR, (4) XFORWARDED, (5) FORWARDEDFOR, or (6) FORWARDED HTTP header to index.php.
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/adminusers.php to bypass a protection mechanism against direct request.