Earlier this month
Photopost sent its customers an email advising of an exploit affecting all versions of Photopost vBGallery, that allowed a user to upload a mis-named file that could be executed by your server.
Their excuse is that it is Apache's flaw.
They have provided instructions on how to patch all known versions of vBGallery, and if you hold an unexpired license, you have the option of paying to renew your account to be able to download the latest unexploitable version.
More information
Here
(You cannot download the unexploitable version if your licenses have lapsed).