CVE-2009-3499

Publication date

2009-09-30 15:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.