Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.
http://www.gulftech.org/?node=research&article_id=00069-04202005
http://sourceforge.net/project/shownotes.php?release_id=320768