SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24381
http://www.securityfocus.com/bid/16520
http://www.cyberlords.net/advisories/cl_ubb.txt
http://archives.neohapsis.com/archives/bugtraq/2006-03/0494.html