CVE-2006-3792
SQL injection vulnerability in ServerClientUfo::recv_packet in server_protocol.cpp in UFO2000 svn 1057 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving the packet.c_str function.
Date published : 2006-07-21
http://www.securityfocus.com/bid/19028
http://www.securityfocus.com/archive/1/440293/100/0/threaded