SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/63989
http://www.securityfocus.com/bid/45367
http://www.openwall.com/lists/oss-security/2012/05/01/3
http://www.openwall.com/lists/oss-security/2012/04/30/3
http://www.openwall.com/lists/oss-security/2012/04/30/1
http://www.openwall.com/lists/oss-security/2011/01/03/12
http://secunia.com/advisories/42346
http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4
http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10