SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.Referenceshttp://www.securityfocus.com/bid/35049https://www.exploit-db.com/exploits/8751http://secunia.com/advisories/35139