You may upgrade to XenForo 1.5.10 (or any subsequent version) to fix this issue. You should upgrade as you would to any other release. See further below in this announcement for more details on this release. If you take this approach, you should not apply the patch below.
And also I am confused about this:
If you are running XenForo Media Gallery 1.1.5 or newer, you will automatically be secured from this issue if you follow the instructions in the XenForo 1.5.10 release announcement.