A vulnerability has been reported in Document Library, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "intGroupID" parameter in view_group.asp is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Vulnerable Products
Vulnerable Software: Document Library 1.x
Solution
Edit the source code to ensure that input is properly sanitised.