SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.
https://www.exploit-db.com/exploits/4686
https://exchange.xforce.ibmcloud.com/vulnerabilities/38832