vBulletin "Profile Customization" Feature HTML Injection

  Bookmark
 and Share

vBulletin is a web-based content manager. The application is exposed to an HTML injection issue because it fails to sufficiently sanitize user-supplied input to the "Page Background" field of the "Profile Customization" feature. vBulletin version 4.0.8 is affected.

Ref: http://www.securityfocus.com/archive/1/514756

10.47.17 - CVE: Not Available
Platform: Web Application