SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.
http://www.vupen.com/english/advisories/2005/2250
http://www.securityfocus.com/bid/15243
http://www.hardened-php.net/advisory_172005.75.html
http://www.debian.org/security/2005/dsa-925
http://securitytracker.com/id?1015121
http://securityreason.com/securityalert/130
http://secunia.com/advisories/18098