SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15655
https://docs.xmbforum2.com/index.php?title=Security_Issue_History
http://www.securityfocus.com/bid/9983