Soft: vBTube 1.x (module for vBulletin)
The vulnerability allows a remote user to run XSS attack on the target system. The vulnerability exists due to the lack of processing input data in the parameter "search" scenario vBTube.php. An attacker could execute arbitrary script in the browser victim in the context of a vulnerable site security.
Source:
http://www.kybermoney.uz/news.php?id=354