SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.Referenceshttp://secunia.com/advisories/37748https://exchange.xforce.ibmcloud.com/vulnerabilities/55138http://www.osvdb.org/61347http://www.securityfocus.com/bid/37488http://www.maxdev.com/Article661.phtml