Any of my friends had problems with SQL injection on his forum (admin account was hacked), but he used IPB 2.3.6. To IPS 4 I don`t know if this is possibile. Important is that when ppl register, some signs must be not allowed to use, for exampe @ or _. Something which can be part of any SQL command. To him was all allowed and...After he changed this, all was fine, no others attack.