Invision Power Board version 2.1.7 suffers from cross site scripting and SQL injection vulnerabilities.