Any updates on this vulnerability? I had a site hacked twice exactly the same way (base64 encrypted php code was inserted at table 'template' , field 'template' , key record 'spacer_open', which was evaluated and defaced the website). My vBulletin version is 3.7.3 PL1. Modules used (all latest available version):
- MorbiD SuitE [9 Flavours] | LYCHEE new| 3.7.2
- Cyb - Advanced Permissions Based on Post Count
- Automatic Thread Tagger
- Periodic Prune Pms [ Cron Job - Fully Controlable ]
- Separate Sticky and Normal Threads
- Embed XHTML valid YouTube and Google Video into your posts
- Automatic Inactive Users Pruning - vB3.7 RC2
- vbAnonymizer
- GTCustom Pages - Create Custom Pages With Ease
- Send emails with HTML as HTML