SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.
http://www.vupen.com/english/advisories/2006/0475
http://www.securityfocus.com/bid/16538
http://www.securityfocus.com/archive/1/424335/100/0/threaded