From the Secunia advisory at http://secunia.com/advisories/42343/: DESCRIPTION: A vulnerability has been reported in phpBB, which can be exploited by malicious users to conduct script insertion attacks. Input passed via the "[flash=]" BBCode parameter when creating a post is not properly sanitised before being used in includes/message_parser.php. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed. The vulnerability is reported in versions prior to 3.0.8.
3.0.8 is now in CVS.
(In reply to comment #1) > 3.0.8 is now in CVS. Thank you. Could you also remove previous, vulnerable versions from the tree?
(In reply to comment #2) > Thank you. Could you also remove previous, vulnerable versions from the tree? Sorry, I forgot to do that. Done now. :)
Thanks folks. Closing noglsa.