University of Victoria

The phone number text entry box on the data entry page appears to have the user input directly concatenated to a SQL query. Because of this, the user was able run SQL commands directly against the database viewing the data from other users as well as specific information about the database. ................