WHID 2006-22: SQL injection in a banking application

Attack Information
WHID ID: 
2006-22
Date Occured: 
12 Apr 2006
Attack Method: 
Outcome Information
Outcome: 

A CIO of a bank in Singapore reports that many application layer vulnerabilities, including SQL injection, where discovered in a banking application they purchased before it was put into production.

Additional information: