There are 2 files that have holes in the forum security. Search.pl and editprofile.pl. If you are running 3.4 you can either grab the latest release or you can grab the attached zip that has the 2 fixed files in it.

---
'If it's worth doing, It's worth doing loudly'
Scream