WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
webchess project webchess 1.0