SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/12366
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-0480
http://www.securityfocus.com/bid/7979