njs12345 recently brought this to my attention in the mIRC chat room…
http://www.securitytracker.com/alerts/2002/Dec/1005803.html
I find it quite interesting. Do you know if vBulletin has fixed this security flaw? If not, I think we should probably disable HTML in posts or at least certain tags maybe?
I know in this link it says
Vulnerable Versions:
2.2.7
2.2.8
But it also has no versions under the Non-Vulnerable Versions, so I don’t know if it is fixed or not.
It should be something to look into though.