SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
https://bogner.sh/2015/09/winpat-portal-3-unauthenticated-sql-injection-exploit/