CVE-2006-2954
SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.
Date published : 2006-06-12
http://www.securityfocus.com/bid/18367
http://pridels0.blogspot.com/2006/06/officeflow-26-vuln.html