http://isc.sans.org/diary.php?date=2005-12-25
phpBB <= 2.0.17 exploit code in the wild
Published: 2005-12-25,
Last Updated: 2005-12-25 00:45:05 UTC by Kevin Liston (Version: 1)
It's an early holiday gift for phpBB admins all over the world. Exploit
code affecting phpBB version 2.0.17 and previous has been made public.
The targeted vulnerability was announced on Halloween, and updates have
been available since then.
I predict we'll be seeing profile.php probes appear in your web logs
right along with the awstats and xml-rpc attacks that you've been
getting.
http://www.frsirt.com/exploits/20051224.r57phpbb2017.pl.php
Advisory ID : FrSIRT/ADV-2005-2250
Rated as : High Risk
Note : This vulnerability is currently being exploited in the wild