Originally Posted by Simon Lloyd
Yes I have VBSEO although I cant' even remember what it does.
It was definitely the ajax.php file in 3.6.8 - the guys at Total Server Solutions tried a test of the exploit on it and it worked. They put on a vb 4.x ajax.php file and tried the exploit, and it didn't work.
Exploit in 3.6.8 ajax.php (example):