The phpbb_clean_username function in phpBB has an improper order of execution allowing path and SQL table disclosure.