LinPHA versions 0.9.4 suffers from SQL injection attacks due to an input validation error in the session.php script.