[原文]SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) read.php, and the (3) search and (4) debut parameters in (b) index.php.
CS-Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the read.php script not properly sanitizing user-supplied input to the 'id' and 'debut' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
Upgrade to version 0.82 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.