SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.
https://www.exploit-db.com/exploits/4678
https://exchange.xforce.ibmcloud.com/vulnerabilities/38774
http://www.neocrome.net/page.php?id=2349