As posted at vBulletin.com:
vBulletin 2.3.10 Released
vBulletin 2.3.10
Following the internal discovery of a potential cross-site scripting flaw, we have decided to put out a preventative security release in order to close the hole before it is exploited.
For the vBulletin 2.3.x branch, the problem can be resolved in one of two ways:
- Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 2.3.10 package from the vBulletin Members' Area and following the regular upgrade procedure.
- Patch: A second option is to download the patch file in the Members' Area and upload them to your web server, overwriting the admin/functions.php file.
Please do note that vBulletin 2.3.x and 3.0.x are reaching the end of their lives and is are longer actively developed, except for bug fixes. If you have not yet upgraded to a more recent version of vBulletin, you should consider doing so.
Upgrade Instructions:
Instructions for upgrading to vBulletin 2.3.9 are available
here.
Read more at vBulletin.com