SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.
- http://packetstormsecurity.org/1006-exploits/brightsuite-sql.txt
No PoCs found on GitHub currently.