SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 and CVE-2013-6931.
https://support.cybozu.com/ja-jp/article/7993
http://www.securityfocus.com/bid/65809
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000024