CVE-2008-1968
Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.
Date published : 2008-04-27
http://www.securityfocus.com/bid/28773
http://www.securityfocus.com/archive/1/490843/100/0/threaded