The profile.php script in 427BB is susceptible to cross site scripting and remote command execution flaws.