CVE-2009-2776
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Date published : 2009-08-14
http://packetstormsecurity.org/0907-exploits/smartasp-sql.txt