Quicksilver Forums versions 1.4.2 and below suffer from local file inclusion and malicious avatar upload vulnerabilities.