CVE-2007-3909
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.
Date published : 2007-07-19
http://www.securityfocus.com/bid/25094
http://www.portcullis-security.com/uplds/advisories/Bandersnatch%20-%2007-006.txt