ForumPal version 1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.