Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
https://exchange.xforce.ibmcloud.com/vulnerabilities/30786
http://www.debian.org/security/2008/dsa-1488