SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/13867
http://www.phpbb.com/phpBB/viewtopic.php?t=153818
http://marc.info/?l=bugtraq&m=107196735102970&w=2