I want to add to the topic: phpBB 2.0.23 is considered unhackable at the moment(PHP vulnerabilities not included of course).
Just another news story about phpBB... http://it.slashdot.org/article.pl?sid=08/03/17/2358207 and some more info from WikiPedia: http://en.wikipedia.org/wiki/Phpbb#Security