Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the forum_id parameter to options.php or (2) lastvisited parameter to viewforum.php.
http://www.vupen.com/english/advisories/2005/2504
http://www.securityfocus.com/bid/15502