The source of the problem, says Fredrick Lee, a software security researcher with Fortify Software, the application vulnerability specialists is poor coding on the state's Department of Corrections Web site.
"This is a classic SQL injection vulnerability," he said, adding that, in this case, the security lapse could easily have been caught with a simple code review.
According to Lee, had some form of automated analysis been part of the release procedure for this Web site, the incident could have been avoided.
"The sad thing is that vulnerabilities like these indicate to attackers that other related applications and organizations are probably vulnerable as well," he said.
According to newswire reports, anyone with a basic knowledge of SQL programming could interpret the URL and other data returned by the Oklahoma DoC Web site.

Have you read these related articles?
Newsletter: