bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.Referenceshttp://secunia.com/advisories/61794http://www.minibb.com/forums/news-9/blind-sql-injection-fix-6430.htmlhttp://security.szurek.pl/minibb-31-blind-sql-injection.html