The hosting team 'fixed' the PHP install on the site so that I can now change the active version. We are now on the latest PHP (5.4) as 5.2 was no longer supported, and the latest vbulletin 4.2.2 which fixes both this hack and the cross-site scripting vulnerability.
Tim
Tim