SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
seacms seacms 6.64