CVE-2009-3788
SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.
Date published : 2009-10-26
http://www.securityfocus.com/bid/36777
http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt