SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/52088
http://www.exploit-db.com/exploits/9289