Originally Posted by iogames
do they really get your password? or just they got a way to enter?
They can just initiate a login process - they don't know your password, but they are logged in as you. Similar to the "Admin Log In As User" modification.
Originally Posted by iogames
how we can avoid that?
how many files of this kind there's?
How can you avoid it? Don't let anyone be able to upload files files directly. (Attachments are OK, they are correctly stored by vBulletin.)
How many of these files are there? There are probably thousands of shells available to freely download.