SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26376
http://www.securityfocus.com/bid/17904
http://www.securityfocus.com/archive/1/433564/100/0/threaded