CVE-2006-4585
SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
Date published : 2006-09-06
http://www.securityfocus.com/bid/19834
http://www.securityfocus.com/archive/1/445079/100/0/threaded