When user profile pictures are enabled, the default user profile validation function will be bypassed, possibly allowing invalid user names or e-mail addresses to be submitted.
This issue only affects Drupal 6.x.
Vendor Status:
Drupal issued an update for this vulnerability