SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9083
Reference (s):
- http://seclists.org/fulldisclosure/2019/Feb/51

