CVE

Id
40934  
CVE No.
CVE-2009-3499  
Status
Candidate  
Description
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.  
Phase
Assigned (20090930)  
Votes
None (candidate not yet proposed)  
Comments