Check out cgi-bin/ubb_profile.cgi, line 457 and consider adding " || ($key eq 'signature')" right before the ") {".
Note that it's really not recommended to allow HTML in signatures: for example, if the HTML exploit checking rules get stricter, the existing signatures won't follow them.