Originally posted by Ultimate Weapon
According to what said yesterday, yes.
Yeah, their track record with forum software (heck, with websites in general) is appalling. It's pure luck as far as I can tell that the forum was kept on a separate server account ( rather than .com or .ca) and the rest of everything didn't get wiped and defaced.

Nasty thing:

The worm spreads via phpBB prior to 2.0.11; it isn't directly related to the general vulnerabilities addressed within php 4.3.9 and earlier, although that's also potentially a serious threat in the wild at the moment.
