SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).Referenceshttp://www.securityfocus.com/bid/32599https://exchange.xforce.ibmcloud.com/vulnerabilities/47033http://packetstormsecurity.org/0812-exploits/jbook-disclosesql.txt