Description
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Problem types
CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10861-b8709-1.html
www.twcert.org.tw/en/cp-139-10863-2f48e-2.html