The file SSI.php has a number of functions to return information about the status of the forum (statistics). Functions 'welcome' and 'recentTopics' are vulnerable to SQL
injection because the parameter ID_MEMBER is not properly checked.
An exploit is available but the YaBB SE team relased a patch. You should upgrade to 1.5.5 to be safe.
This is probably the last version of this forum. The team start working on a new forum software called SMF.
You can find the patch on YaBB SE website: http://www.yabbse.org/