SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters.
https://www.exploit-db.com/exploits/6814
https://exchange.xforce.ibmcloud.com/vulnerabilities/46067