Juraj,
Thanks for the information! I was able to query the CMS_Category for CategoryID = 62. The page in question includes multiple configured repeaters, but I wasn't able to find the specific query anywhere on the page. Since the query referenced in the original question was executed internally using the Kentico database account, it's unclear whether this constitutes a true SQL injection attack. Are there any settings within the CMS administration interface that automatically sanitize query string parameters to help mitigate vulnerabilities like cross-site scripting (XSS) and SQL injection?
Thanks,
SR