-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - -------------------------------------------------------
 GERMAN COMPUTER FREAKS - SECURITY ADVISORY - SINCE 1997
                  January 20st, 2003
- - -------------------------------------------------------
  Software      : vBulletin Bulletin Board
  Vendor        : Jelsoft Enterprises Limited / inGame GmbH
  Vulnerability : Cross Site Scripting
  Status        : Author has been notified
- - ------------------------------------------------------
- - - - Description
    vBulletin Bulletin Board derivatives contain a security bug
   that may lead to disclosure of private informations due to a
   cross site scripting attack.
    This vulnerability may enable an attacker to transmit sensitive
   informations like 'encrypted' passwords, user identification
   numbers or forum passwords to another server.
    Currently, we will refrain from publishing proof of concept
   information to mitigate the impact of this vulnerability.
- - - - Technical Details
    Due to an improper quoted field in register.php it's possible
   to inject malicious HTML code. With the use of Javascript code
   an attack is then able to send sensitive informations (like
   cookies) to a foreign server.
   Attack Example: