All vBulletin versions from 2.0.0 to 2.2.8 have a cross-scripting security loophole that allows people to get member's usernames and passwords off your forum by doing something quite simple.
A fix is provided while the vB team organizes version 2.2.9 -
Read about it here:
http://www.vbulletin.com/forum/showt...threadid=57025
John posted a replacement global.php in vB.com's announcement forum, but PPN posted a more updated global.php at the bottom of this page:
http://www.vbulletin.com/forum/showt...5&pagenumber=5
Do upgrade to protect the security of your site. A friendly reminder post for vB admins.