Sorry in advance for my bad english but I'm italian wink.gif

Ok.. I installed the latest phpBB release on my own system and tried this out: it works.

If the phpBB HTML option is "ON" you can execute javascripts using the [URL] tag.
We can use this vulnerability for cookie stealing.

EXAMPLE:
> Create a new post and insert a link in this way: