Oxygen versions 1.x and below suffer from a SQL injection flaw.
ef3e14a2509956d8d4e51b79c96575aae973a70d70ff1584deea0f3505f5d1ad
author: DaBDouB-MoSiKaR [Moroccan Security Team]
site: www.o2php.com
greetz to : [Moroccan Security Team] CiM-TeaM and All Freinds
Solution: intval()
exemple:
https://[target]/post.php?action=newthread&fid=[sql]
inbox:DaBDouB-MoSiKaR[at]moroccan-security[dot]com