SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6944
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1452
http://www.securityfocus.com/bid/3142