An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.