SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote malicious users to execute arbitrary SQL commands via the cat_id parameter.
vastal i-tech buddy zone 1.5