http://forums.invisionpower.com/index.php?showtopic=213374 theres the link, you need to patch it ASAP. My forum was already exploited by one of my members. Lucky for me it was an honest member and he actually showed me what happen and how he did it. You need to go update your forums. This exploit gives people access to your ACP.
Another patch for invision was released today, it upgrades you to version 2.1.6. It is something to worry about as they are able to run sql queries on your database.