SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405