Exploit Title : Cross Site Scripting ( XSS - Stored ) vulnerability in vBulletin SEO Plugin vBSEO. Found By : Yogesh Jaygadkar | http://www.jaygadkar.com/ Tested versions : vBSEO 3.2.0 & vBSEO 3.6.0 Tested with : vBulletin 4.0.6 & vBulletin 4.2.1 Vulnerable POST Parameter : sendtrackbacks Greetz to : Darshit Ashara, Rahul Sasi, Aditya Gondela Team Indishell & garage4hackers POC : http://www.VictimVBForum.com/forum/newreply.php?do=postreply&t=[Thread ID] http://www.VictimVBForum.com/forum/newthread.php?do=newthread&f= In Advanced Reply Or New Thread page, Put your ">vector in "Trackback" Options. Submit the Reply. ( You can also test it by clicking Preview Post button ) Done ;)