22
At a first glance at the logs it appears the intruder was using newBB just before, during, and immediately after gaining access. Also, the PHPSESSIONID is exactly the same throughout that log sequence although it comes from two different IP's. I didn't know that was possible.
It also looks like "/modules/newbb/viewtopic.php topic_id=2&forum=1" was important during the core sequence up to gaining admin access. After that, it's not used anymore.
Those are just observations of the log. Exactly what it means within the XOOPS framework I don't know.
Good luck.
jaquita