# Title: vBulletin Version 3.5.2 - Introduction XSS scripting # Author: Discovered by ROOT_EGY # Version: vBulletin Version 3.5.2 =============================================== WWW.sec-war.com =============================================== 3.5.2 - Introduction XSS scripting The vulnerability is in the field «title» scenario «calendar.php». Example: TITLE :---> Test