HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $SERVER['HTTPUSERAGENT'] parameter to exampleform.ajax.php or example_form.php.