The vulnerabilities are caused due to some unspecified errors in the avatar handling functions and may be exploited to disclose and delete arbitrary files.
Some issues disclosing the full path to certain scripts have also been reported.
This means that phpbb 2.0.12 has now been released, with more information available here: phpBB 2.0.12 released
Posted by brian_turner at February 22, 2005 07:18 PM