Frontaccounting Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2009-4037
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 and 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc and various other .inc and .php files under (2) admin/ (3) dimensions/ (4) gl/ (5) inventory/ (6) manufacturing/ and (7) purchasing/.