CVE-2006-3161
SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the action parameter.
Date published : 2006-06-22
http://www.securityfocus.com/bid/18501
http://www.securityfocus.com/archive/1/437659/100/0/threaded