CPA Lead Reward Script allows SQL Injection via the username parameter.
cpa lead reward script project cpa lead reward script -