SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20059
http://www.securitytracker.com/alerts/2005/Apr/1013676.html