
An XSS flaw within the user profile customization was recently reported to us. On initial investigation it appeared that the flaw would only affect the user who attempted to perform the exploit when visiting their own profile page. Additional reports we have since received, confirm that certain visitors utilizing Internet Explorer 6 and specific variants of Internet Explorer 7 may be exposed to this exploit.
The exposure to other users that utilize IE6 and certain variants of IE7 has been rectified with this patch.
This issue only affects vBulletin 4.0.8 where User Profile Customization has been enabled by the administrator. No other versions of vBulletin are affected. Versions of vBulletin 4.0.8 that do not have User Profile...