
DescriptionphpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
As discussed with the phpbb maintainers; this is only a lack of feature
(phpbb2 doesn't allow a kind of rate control for maximum login/searches for
a certain time frame), but not a directly fixable security problem

