PHPWebThings version 1.4 suffers from SQL injection, credential disclosure, and remote command execution vulnerabilities.