Invision Power Services versions prior to 2.0.4 suffer from cross site scripting and SQL injection vulnerabilities.