Risk: Low
The latest vulnerability is in phpBB-2.0.18 (although other versions may also be affected), which was a popular target during 2005.
The vulnerability can only be exploited by changing default settings to values that will open your web server to numerous other problems. It is also possible to disclose the full path to "admin/admin_disallow.php" by accessing it directly with the "setmodules" parameter set to "1" (requires that "register_globals" is enabled).
To resolve the problem, upgrade to version 2.0.19.