SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/71880http://www.securityfocus.com/bid/51105http://www.vulnerability-lab.com/get_content.php?id=362http://www.exploit-db.com/exploits/18249