SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.
https://github.com/Akityo/TOPSEC/issues/1
http://www.huilan.com/zkhl/resource/cms/2015/09/2015091814311792443.pdf