Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.
https://exchange.xforce.ibmcloud.com/vulnerabilities/31119
http://www.securityfocus.com/archive/1/455414/100/0/threaded
http://www.securityfocus.com/archive/1/455351/100/0/threaded
http://www.securityfocus.com/archive/1/455265/100/0/threaded