CVE-2007-3987
SQL injection vulnerability in SearchResults.asp in ImageRacer 1.0, when WordSearchCrit is enabled, allows remote attackers to execute arbitrary SQL commands via the SearchWord parameter.
Date published : 2007-07-25
http://www.securityfocus.com/bid/25010
http://www.securityfocus.com/archive/1/474419/100/0/threaded