SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.
- https://www.exploit-db.com/exploits/1686
No PoCs found on GitHub currently.