microBlog version 2.0 RC-10 does not properly sanitize the $month and $year variables which can lead to SQL injection.