A vulnerability has been reported in DMXReady Polling Booth Manager, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "QuestionID" parameter to inc_pollingboothmanager.asp (when "view" is set to "results") is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.