SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action.Referenceshttp://osvdb.org/58293http://www.vupen.com/english/advisories/2009/2741http://secunia.com/advisories/36826http://packetstormsecurity.org/0909-exploits/bpstudent-sql.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/53428