Hi everyone,
For those using PHPBB on their website, please note that version 2.0.16 has been released:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=302011This fixes an exploit in 2.0.15 which allowed arbitrary PHP code to be run on the server:
Due to a bug in the phpBB highlighting code it's possible to inject
PHP-code into the running script. E.g. It's possible to run system
commands if the PHP interpreter allows system() and simular functions.
This is actually based on an old bug which was improperly fixed in
phpBB 2.0.11.
We kindly request that anyone running 2.0.15 or earlier versions of PHPBB2 upgrade to the newest available version. The upgrade should be fairly simple, however if you would like any assistance, please do log a ticket in our helpdesk and we will happily help you in doing so.