RaceEventManagement version 0.7.6 is susceptible to SQL injection and cross site scripting attacks.
eae1cab37f222ee56b41cd2dc14d93a3307e898d69f32be0db85d225c3653de6
============================
Discovery By: Mr-X
Site: www.alshmokh.com
E-mail: Mster-X@hotmail.com
===========================
Example:
/nennung.php?pid=[SQL]
/nennung.php?pid=[XSS]