Secunia (secunia.com/advisories/20158/) writes:
Description:
Some vulnerabilities have been reported in Invision Power Board, which potentially can be exploited by malicious users and malicious people to compromise a vulnerable system.
Input passed to unspecified parameters is not properly sanitised before being used, which may be exploited to execute arbitrary PHP code.
The vulnerabilities have been reported in version 2.0.4 and 2.1.6. Other versions may also be affected.
Solution:
Apply patches
http://forums.invisionpower.com/index.php?showtopic=215527