phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24327
http://www.securityfocus.com/archive/1/423030/100/0/threaded