It's just cursed, messages.php has yet another security issue (I've lost count now). Well, not to worry, an Italian support member, lnx85, has produced a fix. I have updated the two sourceforge packages and added the fixed file to patch 307, so this file is for existing users only. I fully intend to replace this script once v6.00.4 is released. Please make sure you update asap.