"Search.php" in Punbb versions 1.2.8 and earlier does not properly validate user-supplied input. A remote user can create specially crafted parameter values that will execute SQL commands on the underlying database. POC included.
ef14a68dd3dad542f61ee592dc81bdb6aebfcf8062ee30128e663c593850becf