A note for all phpBB 2.0.x administrators from phpBB.com:
We've been notified by Niels Teusink of a flaw in search.php. This, under the right circumstances with certain server versions be exploited to obtain password hashes. The chances of this being taken advantage of on wide scale are slim.
Instructions on fixing the problem can be found
here. All existing installations of phpBB 2.0.x are vulnerable, however the 2.0.6 archives have been updated, so installations after November 24 will be patched.