SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.Referenceshttp://www.securityfocus.com/archive/1/497279/100/0/threadedhttp://www.securityfocus.com/bid/31740