Woltlab Burning Board 2.0 RC 1 has a vulnerability that allows any user (even guests, depending on the configuration) to compromise every other account due to a variable containing unchecked user input in board.php, which can be used for a sql injection attack.
c4137ea31f5a97b9986a26c210deb1ab9aecbe8674896eed48684916a74e6911