IBL Online Weather prior to 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
iblsoft online weather