A web site (picasa.google.com) belonging to Google has been defaced on saturday by the Brazilian defacer Xfaulz.
Picasa is a software package for managing photos, the company has been acquired by Google earlier this year. The server hosting the Picasa web site isn’t part of the Google network, Xfaulz compromised it by exploiting the highlight parameter processing vulnerability in phpbb2 (some exploits allowing remote command execution are publicly available), the forums of Picasa are available at http://forums.picasa.com. According to our database, this defacement remains the only digital attack against Google Inc.
The screenshot of the defacement is available here: http://www.zone-h.org/en/defacements/mirror/id=1775926/.
For more informations regarding the vulnerability, check: http://seclists.org/lists/bugtraq/2004/Nov/0185.html