SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.
http://www.vupen.com/english/advisories/2005/0558
http://www.gulftech.org/?node=research&article_id=00075-05162005